BEEOS CLOUD / DEVELOPER REFERENCE
Security and ownership
Keep organization, app, end-user, runtime, and data-channel permissions separate
An organization contains apps. A bsk_ server key fixes the organization and app context for Cloud Server API calls. The product backend owns its user directory and passes an opaque app-local external user ID to scope relevant Cloud requests. Cloud stores session and resource linkage for that ID; it does not authenticate the product user on behalf of the app.
| Actor | May hold | Must not receive |
|---|---|---|
| Product backend | bsk_, product session, user-to-external-ID mapping | Runtime token unless explicitly operating the runtime |
| Agent runtime | Runtime token and instance/agent IDs | Product server key |
| Product app | Product session and short-lived descriptor | bsk_ or runtime token |
Server identity.createClientSession issues a scoped client token. Refresh can narrow capabilities; revocation invalidates a session. External-user deletion is an asynchronous operation; retrieve its status with getExternalUserDeletion. These routes exist in the Cloud Server API. Ensure the authenticated product user is allowed to access the external ID before the backend calls them.
Treat presigned file URLs and WebRTC/ACP/Canvas descriptors as bearer capabilities with limited scope and lifetime. Verify task webhook signatures over the raw request bytes. The backend uses the Server SDK for Cloud operations and its own authenticated user real-time channel for product events. The product frontend displays those events and opens only the data connections explicitly authorized by a descriptor; observing a stream does not grant command authority.