Skip to content

Authentication tokens

The gateway recognises three distinct token types. Each type authorises a different set of operations.

Gateway token

A gateway token authorises inference requests against the /v1/ endpoints of one specific gateway. Created by a tenant admin from the Gateways view. Bound to a gateway, not to a user.

Used in the Authorization: Bearer <TOKEN> header of inference requests.

Personal access token

A personal access token authorises inference requests on behalf of a single user account. Created by the user from the Account › Profile page. Bound to a user and a gateway.

Each token carries its own budget and rate limit, set when the token is created — they are not inherited from the user account. A token also carries a set of scopes, which default to ["inference"]. Used in the Authorization: Bearer <TOKEN> header of inference requests.

The plaintext token (prefixed myra_) is shown only once, at the moment of creation; the gateway stores only its SHA-256 hash and cannot display the token again. Record it then or generate a new one.

Admin session

An admin session authorises requests against the admin API at /admin/v1/. Issued by signing in to the SPA at ai.myra.eu. Carried in the aig_admin cookie.

The admin session is not used for inference. Inference requests must use a gateway token or a personal access token.

Comparison

Token type Authorises Created by Used in
Gateway token inference (/v1/) on one gateway tenant admin Authorization header
Personal access token inference (/v1/) on one gateway, as the user the user Authorization header
Admin session admin API (/admin/v1/) sign-in flow aig_admin cookie

See also

  • Profile — how to create and revoke your personal tokens (Account › Profile)
  • Users — how to manage other users' tokens