Skip to main content
Platform features need a Cordango workspace. You can sign up here and create one in a few minutes. The open foundation, meaning the CLI, the compiler and the standalone generator, needs no account and is available to everyone.
Requests authenticate with a personal access key presented as a bearer token.

Creating a key

On your instance, open your avatar menu and choose Personal Access Keys. The secret is shown once, at creation. Keys are managed under /api/me/access-keys:

The token format

A token is a dotted string with a fixed, scannable prefix.
The prefix exists so a leaked credential is recognisable to a secret scanner on sight. The key id sits apart from the secret so a key can be identified in a log or an audit entry without that log holding anything usable. An exchange token also encodes the instance address and tenant. That’s a convenience for cordango login rather than an authority. The address inside a token is a claim the server confirms. See Publishing.

What a key can do

A key acts as you. It carries your relationships and the roles those grant, so it can reach exactly what you can reach and nothing else.
cordango logout forgets a credential on the machine it runs on. It doesn’t revoke it. To make a key stop working everywhere, delete it on the instance.