> For AI agents: the complete documentation index is available at /llms.txt, the full documentation bundle is available at /llms-full.txt.

# Authentication and workspace matching

> **Availability:** The DevBase runtime and production API are not yet deployed. This page describes the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.

Customer backends authenticate with a server-side API key in the HTTP Authorization header:

```http
Authorization: Bearer devbase_live_…
```

Keys are never publishable browser credentials and customer OAuth M2M is not supported. API-key issuance and revocation are managed in the Logto-authenticated DevBase web console. A key is shown only once, can expire or be revoked, and is stored by DevBase as a digest.

Every request must name an active `workspaceId`. The key must belong to that exact workspace and include every scope declared by the RPC policy. Unknown, archived, revoked, expired, wrong-workspace, or insufficient-scope calls are denied without revealing cross-workspace resources.

API-key calls do not enable browser CORS. Keep keys in a trusted server environment.
