MASAKA / Security / Authentication
Security

Use the credential
for the boundary.

Account identity, project automation, input control, and direct preview use distinct credentials with different lifetimes.

Credential types

CredentialWhereScope
Account access tokenDashboard / signed-in web clientOwned user and project resources
msk_… project keyTrusted server or harnessSessions, profiles, commands
Control capabilityBrowser mutationOne session and epoch
Preview ticketDirect worker connectionOne session, mode, and short expiry

HTTP headers

Trusted server
Authorization: Bearer $MASAKA_API_KEY
Content-Type: application/json

# signed-in clients also select the owned project
X-Masaka-Project: <project-id>

Rules

  • Keys are shown once; lists return only prefix and timestamps.
  • Project keys cannot access billing, account settings, or plaintext vault values.
  • Do not log capabilities, view tickets, or credentials.
  • Rotate a key if it may have entered chat, source, a commit, or a browser bundle.