Authentication tokens
The gateway recognises three distinct token types. Each type authorises a different set of operations.
Gateway token
A gateway token authorises inference requests against the /v1/ endpoints of one specific gateway. Created by a tenant admin from the Gateways view. Bound to a gateway, not to a user.
Used in the Authorization: Bearer <TOKEN> header of inference requests.
Personal access token
A personal access token authorises inference requests on behalf of a single user account. Created by the user from the Account › Profile page. Bound to a user and a gateway.
Each token carries its own budget and rate limit, set when the token is created — they are not inherited from the user account. A token also carries a set of scopes, which default to ["inference"]. Used in the Authorization: Bearer <TOKEN> header of inference requests.
The plaintext token (prefixed myra_) is shown only once, at the moment of creation; the gateway stores only its SHA-256 hash and cannot display the token again. Record it then or generate a new one.
Admin session
An admin session authorises requests against the admin API at /admin/v1/. Issued by signing in to the SPA at ai.myra.eu. Carried in the aig_admin cookie.
The admin session is not used for inference. Inference requests must use a gateway token or a personal access token.
Comparison
| Token type | Authorises | Created by | Used in |
|---|---|---|---|
| Gateway token | inference (/v1/) on one gateway |
tenant admin | Authorization header |
| Personal access token | inference (/v1/) on one gateway, as the user |
the user | Authorization header |
| Admin session | admin API (/admin/v1/) |
sign-in flow | aig_admin cookie |