Security & Access

ReferenceWhat it covers
SecretsSecret record fields, value disclosure rules, storage backends, and create/update/delete lifecycle.
API keysManaged API key record fields, status values, expiry and rotation behaviour, and use as a source-auth credential.
Source authenticationThe four ways a surface can authenticate its callers — JWT bearer, API key, API Key Provider, and mTLS — and where each method’s values come from.
RBACThe administrator/poweruser/user role ladder and the full default permission map.