Concepts
Accounts, teams and keys
Your own account and teams, what each role in a team may do, invitations, and which account a call counts against.
Accounts
Everything on the platform belongs to an account, and there are two kinds:
- Your own account. Made the first time you sign in; you are its owner.
- A team. Made in the console with a name, for people who share keys and usage.
Every account has a plan (free until billing exists) and its own monthly allowance of
units (Usage and units). The console acts on one account at a time: the
switcher at the top of every console page chooses it.
Roles in a team
| Role | May |
|---|---|
owner | everything: rename, invite, keys, members, transfer ownership, delete and restore the team |
admin | rename, invite, make and revoke keys, change and remove members below the owner |
member | read the team, its members, its key ids and its usage |
A team has exactly one owner. Ownership moves only by a transfer, which makes the old
owner an admin. Anyone may leave a team except its owner. A team you are not in answers
404 not_found, never 403, so an id cannot be probed.
Invitations
An owner or admin invites an e-mail address as admin or member. The console shows the invitation link once; it is good for seven days and for one use. Accepting needs a signed-in person whose verified e-mail address is the one invited. No mail is sent: the person who invites passes the link on.
Keys belong to an account
A key is made for one account and every call made with it counts against that account: its allowance, its usage, its limits. Owners and admins make and revoke keys; members see the key ids. An account holds at most ten active keys. A key keeps the scopes it was made with; to change them, make a new key and revoke the old one (Authentication).
Which account a call counts against
GET /v1/me names it under org: for a key, the account the key belongs to; for a
person, their own account. GET /v1/accounts/me answers that account with its plan
and, for a key, the key's name and when it was last used.
Generate an SDK for your account
A client in Rust, TypeScript, Go, Python, C# or Java with exactly the operations your credentials may call, for one account or several, checked by the compiler and by a CI step when the API's cut moves.
Domains
Prove with one DNS TXT record that an account controls a domain, with the steps for each common DNS provider, the API calls, and how the proof is kept true.