BEEOS CLOUD / DEVELOPER REFERENCE
Authentication and ownership
Keep Cloud server keys, runtime identity, and app sessions on their intended sides
Three separate credentials
| Credential | Used by | Sent to |
|---|---|---|
bsk_ server key | Product backend | Cloud Server API URL for the selected environment |
| Runtime token | Agent process | Agent Gateway and Message Service with instance and agent ID headers |
| Product session | Product frontend | Product backend and its user event channel |
| Purpose-scoped descriptor | Product frontend | Only the named data endpoint, within its scope and lifetime |
The Server SDK adds Authorization: Bearer <bsk_ key>; mutations taking an idempotency key set Idempotency-Key. Versioned updates send If-Match using the resource version. Keep the server key in backend secret storage.
Scope the client with cloud.withExternalUser(id) (Python: with_external_user, Go: WithExternalUser); the SDK sets X-BeeOS-External-User-ID. The product backend owns the actual user account and maps it to this opaque, app-local ID; Cloud uses the ID to scope requests and sessions, without becoming the product's user directory. Client-session issuance, refresh, revocation, and external-user data deletion are Server API routes; use the typed SDK identity methods. A browser never receives the server key.
The Harness SDK adds Authorization, X-BeeOS-Instance-ID, and X-BeeOS-Agent-ID. The product backend authenticates and authorizes its users, issues or obtains purpose-scoped descriptors, and supplies them to the frontend for the named data endpoint. Product events remain on the product backend's own user real-time channel. See security and ownership and product frontend integration.
Important: Keep the
bsk_key on the product backend. Do not put the server key or agent runtime token in browser or mobile code.