MASAKA / Security / Authentication
Use the credential
for the boundary.
Account identity, project automation, input control, and direct preview use distinct credentials with different lifetimes.
Credential types
| Credential | Where | Scope |
|---|---|---|
| Account access token | Dashboard / signed-in web client | Owned user and project resources |
msk_… project key | Trusted server or harness | Sessions, profiles, commands |
| Control capability | Browser mutation | One session and epoch |
| Preview ticket | Direct worker connection | One session, mode, and short expiry |
HTTP headers
Authorization: Bearer $MASAKA_API_KEY
Content-Type: application/json
# signed-in clients also select the owned project
X-Masaka-Project: <project-id>Rules
- Keys are shown once; lists return only prefix and timestamps.
- Project keys cannot access billing, account settings, or plaintext vault values.
- Do not log capabilities, view tickets, or credentials.
- Rotate a key if it may have entered chat, source, a commit, or a browser bundle.