Platform features need a Cordango workspace. You can
sign up here and create one in a few minutes. The open
foundation, meaning the CLI, the compiler and the standalone generator, needs no account and
is available to everyone.
Requests authenticate with a personal access key presented as a bearer token.
Creating a key
On your instance, open your avatar menu and choose Personal Access Keys. The secret is shown
once, at creation.
Keys are managed under /api/me/access-keys:
A token is a dotted string with a fixed, scannable prefix.
The prefix exists so a leaked credential is recognisable to a secret scanner on sight. The key id
sits apart from the secret so a key can be identified in a log or an audit entry without that log
holding anything usable.
An exchange token also encodes the instance address and tenant. That’s a convenience for
cordango login rather than an authority. The address inside a token is a claim the server
confirms. See Publishing.
What a key can do
A key acts as you. It carries your relationships and the roles those grant, so it can reach exactly
what you can reach and nothing else.
cordango logout forgets a credential on the machine it runs on. It doesn’t revoke it. To make a
key stop working everywhere, delete it on the instance.