headless.biddevelopers
v1Sandbox console
Sandbox available · Production unavailable

Identity is not auction authority

Authentication answers who is using the Platform. Authorization still has multiple explicit boundaries before a command can affect a Lot.

01User session

Proves a current Platform identity.

02OAuth grant

Names one Workspace, Environment, audience and scope.

03Platform policy

Rechecks current membership and suspension.

04Engine authority

Validates the tenant credential or signed operator decision.

Three credentials, three jobs

CredentialCustodyAuthority
Browser session cookieHosted BFF; opaque to JavaScriptCurrent Platform session only
Platform OAuth grantBFF today; future CLI/MCP host under their release profilesExact Platform resource, context and scopes
Ledgero service credentialTenant backend or sealed Platform custodianEngine administrative calls within its explicit scopes