Sign inCreate account
// 01 / SECURITY

Trust is part of
the protocol.

Concrete controls around identity, credentials, provider dispatch, and the events your application receives.

// 01 / CREDENTIALS

Server-side keys

API keys are hashed at rest and designed for server-side use. Scope and revoke credentials per project.

// 03 / BOUNDARIES

A request crosses
deliberate gates.

01

Authenticate

Bearer key is resolved to an active project.

02

Authorize

Scope, rate, quota, and project state are evaluated.

03

Reserve

Recipient capacity is reserved before provider I/O.

04

Dispatch

The delivery transport accepts the provider request.

// 04 / IMPLEMENT SAFELY

Keep keys on the server.
Verify every event.

Read security guidance Check system status