For AI agents: the complete documentation index is available at /llms.txt, the full documentation bundle is available at /llms-full.txt, and this page is available as Markdown at /devbase/v1/authentication.md.

Authentication and workspace matching

Availability: The DevBase runtime and production API are not yet deployed. This page describes the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.

Customer backends authenticate with a server-side API key in the HTTP Authorization header:

Authorization: Bearer devbase_live_…

Keys are never publishable browser credentials and customer OAuth M2M is not supported. API-key issuance and revocation are managed in the Logto-authenticated DevBase web console. A key is shown only once, can expire or be revoked, and is stored by DevBase as a digest.

Every request must name an active workspaceId. The key must belong to that exact workspace and include every scope declared by the RPC policy. Unknown, archived, revoked, expired, wrong-workspace, or insufficient-scope calls are denied without revealing cross-workspace resources.

API-key calls do not enable browser CORS. Keep keys in a trusted server environment.