DocsStart

BEEOS CLOUD / DEVELOPER REFERENCE

Authentication and ownership

Keep Cloud server keys, runtime identity, and app sessions on their intended sides

Three separate credentials

CredentialUsed bySent to
bsk_ server keyProduct backendCloud Server API URL for the selected environment
Runtime tokenAgent processAgent Gateway and Message Service with instance and agent ID headers
Product sessionProduct frontendProduct backend and its user event channel
Purpose-scoped descriptorProduct frontendOnly the named data endpoint, within its scope and lifetime

The Server SDK adds Authorization: Bearer <bsk_ key>; mutations taking an idempotency key set Idempotency-Key. Versioned updates send If-Match using the resource version. Keep the server key in backend secret storage.

Scope the client with cloud.withExternalUser(id) (Python: with_external_user, Go: WithExternalUser); the SDK sets X-BeeOS-External-User-ID. The product backend owns the actual user account and maps it to this opaque, app-local ID; Cloud uses the ID to scope requests and sessions, without becoming the product's user directory. Client-session issuance, refresh, revocation, and external-user data deletion are Server API routes; use the typed SDK identity methods. A browser never receives the server key.

The Harness SDK adds Authorization, X-BeeOS-Instance-ID, and X-BeeOS-Agent-ID. The product backend authenticates and authorizes its users, issues or obtains purpose-scoped descriptors, and supplies them to the frontend for the named data endpoint. Product events remain on the product backend's own user real-time channel. See security and ownership and product frontend integration.

Important: Keep the bsk_ key on the product backend. Do not put the server key or agent runtime token in browser or mobile code.