Layerbeat
Guides

Authentication

Send `Authorization: Bearer <token>` on every request except the public catalog, signup, login and health checks.

Send Authorization: Bearer <token> on every request except the public catalog, signup, login and health checks.

TokenLooks likeForLifetime
Sessionlb_sess_…People and dashboards. Created by signup or login.7 days, or until you log out
API keylb_live_…Programs and CI. Created with POST /v1/api-keys.Until revoked or its expires_at

Tokens are shown once and stored only as hashes; if you lose one, create another. A revoked key stops working immediately. Call GET /v1/me to check what a token can do.

An API key carries the scopes you choose when creating it (least privilege):

ScopeAllows
vm:readList and read servers, quotes, firewall rules and operations
vm:writeBuy, delete, start, stop, reboot servers; open the console; change firewall rules
ssh_key:read / ssh_key:writeList / add and delete SSH keys
billing:readRead the wallet, its transactions, payment methods and payments
billing:writeStart a USDC wallet top-up

API keys cannot manage API keys, members or the audit log. Those need a session with the right role.