Skip to content

Team and security ​

Everything you build lives in a workspace: your APIs, the people who can manage them and the keys your scripts use. Open it from the workspace menu in the dashboard.

Workspaces ​

Your first workspace is created when you sign up. Create more under New workspace to keep clients or side projects apart, each with its own people, APIs and billing. Admins can rename a workspace, and owners can delete it once its APIs are deleted.

Roles ​

RoleCan do
ViewerSee everything, change nothing
EditorCreate APIs, change pricing, plans, branding and settings, manage customers and credit, reveal the SDK secret
AdminEverything an editor can, plus connect Stripe, change the MicroAuth plan, rotate the SDK secret, set up a custom domain, delete APIs, and manage members, invites and workspace API keys
OwnerEverything, including making other owners and deleting the workspace

Inviting teammates ​

Inviting people comes with the Scale plan: once any API in the workspace is on Scale, admins can click Invite under Members, enter an email and pick a role. The invite expires after 7 days, and pending invites can be revoked. Admins can change a member's role or remove them at any time. The members table also shows who has two step verification on.

Workspace API keys ​

Workspace API keys (mak_...) let scripts, CI and your back office use the platform API, for example to add credit when an invoice is paid. Admins create them under Workspace API keys with a name and a role:

  • Viewer keys can read everything.
  • Editor keys can also change customers, credit, plans and settings.
  • Admin keys can also rename the workspace, manage custom domains and revoke workspace keys.

Some actions always need a person signed in to the dashboard: inviting members, creating keys, connecting Stripe, changing the MicroAuth plan, rotating the SDK secret and deleting an API.

A key is shown once, when it is created. MicroAuth only keeps a hash, so copy it straight into your secret store. The list shows when each key was last used, and Revoke stops it right away. The Workspace ID above the list is what you put in /api/v1/workspaces/{wid} paths.

Activity log ​

Every change is recorded with who made it: a teammate, a workspace key, one of your customers on the portal, Stripe or MicroAuth itself. The workspace page shows the log for the whole workspace, and each API's Activity tab shows just that API.

Search the log, filter it by type of change or by who made it, and click Export to download what you filtered as CSV or JSON. Events are kept for 13 months.

Two step verification ​

Turn it on from Account, under Two step verification:

  1. Click Set up two step verification and scan the QR code with an authenticator app such as 1Password, Google Authenticator or Authy. You can type in the setup key instead.
  2. Enter the 6 digit code from the app and click Turn on.
  3. Save the 10 recovery codes. Each one signs you in once if you lose your phone. New recovery codes replaces them.

From then on, signing in asks for a code after your password. To turn it off you need your password and a current code.

Sign in protection ​

  • Email codes expire after 15 minutes and stop working after 5 wrong tries.
  • Sign in, sign up and code requests are rate limited per address and network, so guessing doesn't scale.
  • Passwords are at least 10 characters and stored as bcrypt hashes.
  • Dashboard sessions use a secure, HTTP only cookie, and every change is checked against the page it came from.

MicroAuth is a product of Zyref, LLC.