Organizations and roles
Every user belongs to at least one organization (signup creates yours). Servers and SSH keys belong to the organization. Credit, payment history and wallet transactions belong to the authenticated use
Every user belongs to at least one organization (signup creates yours). Servers and SSH keys belong to the organization. Credit, payment history and wallet transactions belong to the authenticated user and remain private across shared workspaces. A purchase charges the user placing the order; an API key acts as its creator and charges that user. Workspace membership never grants access to another member's credit. A session acts on your first organization unless you send X-Org-ID: <org id> (you must be a member).
| Role | Can do |
|---|---|
| viewer | Read servers, SSH keys and billing |
| developer | Viewer + buy and manage servers and SSH keys |
| admin | Developer + manage API keys, members (developers and viewers) and read the audit log |
| owner | Everything, including managing admins and other owners |
An organization always keeps at least one owner. Resources of other organizations are invisible to you: asking for one returns 404, exactly as if it did not exist.
Authentication
Send `Authorization: Bearer <token>` on every request except the public catalog, signup, login and health checks.
Servers
Prices are for a prepaid term (`term_months`). When you buy, the price is held from your wallet, charged when the server is running, and released if creation fails. Nothing is charged for a server tha