Authentication and workspace matching
Availability: The DevBase runtime and production API are not yet deployed. This page describes the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.
Customer backends authenticate with a server-side API key in the HTTP Authorization header:
Keys are never publishable browser credentials and customer OAuth M2M is not supported. API-key issuance and revocation are managed in the Logto-authenticated DevBase web console. A key is shown only once, can expire or be revoked, and is stored by DevBase as a digest.
Every request must name an active workspaceId. The key must belong to that exact workspace and include every scope declared by the RPC policy. Unknown, archived, revoked, expired, wrong-workspace, or insufficient-scope calls are denied without revealing cross-workspace resources.
API-key calls do not enable browser CORS. Keep keys in a trusted server environment.