Keys.
A key is a second kind of caller. You make a key in the settings with its grants and its scope. The settings show it once, every call carries it, and the API gateway checks and meters it. One call withdraws a key that leaks.
A person signs in, and a key does not. A key acts for one person or one service, within the scopes and grants that it was made with. The log records every call by key.
Key creation#
- Open the settings and make a key. Name it, and choose the one person or service that it acts for.
- Choose its scopes (a tenant, a brand or a strategy) and its grants.
- The settings show the key once. Store it in your own secret store. No page stores it, and the settings do not show it again.
- Every call carries the key in the
Scale-Keyheader and the scope in theScale-Scopeheader.
Grants#
| grant | allows |
|---|---|
| read | reading the record: entities, leads, signals, monitors, the map, markets, documents and registers |
| ask | questions: the preview, facts, semantic search, neighbours and read-only SQL |
| act | changes within the key’s limits: monitors, plays, moves, actions, leads, the brand’s graph and documents |
| work | long work as tasks, and named procedures |
| files | the local server’s files |
| admin | the tenant’s users, roles, settings and secrets |
A key reads only, unless a grant allows more. A grant carries limits: a budget by kind, a rate, the voices and sending identities, the segments or leads, reversible actions only, and an end date.
Leaked key#
Withdraw the key in one call from the settings. The tenant’s audit trail records every call by key, so you can see what the key touched. The API explorer on this site keeps your key in this browser’s session and nowhere else.
Claims#
| claim | state | route or tool |
|---|---|---|
| The route /v1/act/grant writes a grant, and the route /v1/session/my_grants returns the grants. | target | /v1/act/grant |