Skip to content

Authentication

Myra AI Workspace authenticates inference requests using access tokens. Tokens are issued via the admin UI or the Admin API. Each token carries an expiry date, an optional rate limit, an optional spend cap, and one or more scopes. The gateway stores only a one-way hash of each token — the plaintext is returned once at creation time and cannot be recovered afterwards.

Token format

All tokens begin with the myra_ prefix followed by 64 hexadecimal characters (32 random bytes):

myra_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

The prefix identifies a string as a Myra AI Workspace token, which is useful when auditing secrets managers or configuration inventories.

Token security model

  • Tokens are stored as a one-way hash. The original value cannot be recovered from the database.
  • The plaintext token is returned once in the creation response. Copy it immediately.
  • If a token is lost, delete it and create a new one. There is no recovery path.

Header acceptance order

The gateway looks for an authentication token in the following header order. The first matching header is used:

  1. x-aig-token: <token>
  2. Authorization: Bearer <token>
  3. x-api-key: <token>

This order lets you use the gateway as a drop-in replacement for OpenAI-compatible clients that send Authorization: Bearer or x-api-key without reconfiguration.

Role-based access control

The user_id of each token maps to a user record that has a role field:

Role Inference Admin panel access
admin Permitted Full access, all tenants
tenant_admin Permitted Own tenant — users, settings, and the finance console
ki_manager Permitted Own tenant — groups and workflows only
member Permitted None beyond their own account
finance Permitted Own tenant — finance and cost console only
viewer 403 forbidden via a named user token Own tenant (read-only)

Inference is permitted for every role except viewer (and any unknown or disabled role). A role never determines which gateway a token can reach: every token is scoped to a single gateway, so "inference permitted" means the token is accepted on its own gateway — not on all gateways in the tenant.

⚠️ Caution: The viewer role is intended for users who need read access to the admin UI only. Sending an inference request via a named user token whose user has the viewer role returns 403 Forbidden.

Token types

Two types of token are available. They serve different purposes:

Gateway token User token
Where Settings → Gateways → [gateway] → Auth Tokens card User Management → Users → [user] → + New Token
Fields Expiration only Label, gateway, expiry, budget, rate limit, scopes
Associated with No user identity A specific user record
Budget tracking None Per-user spend tracked
Use case Quick service-to-service token Named credential tied to an identity

Use gateway tokens when you need a simple credential for a service or integration and do not need spend tracking per caller.

Use user tokens when you need to attribute usage, enforce per-user budgets, or manage access for individual people or teams.

Token fields

Field Type Description
label string Human-readable name for the token (valid UTF-8, at most 255 bytes)
user_id string Associates the token with a user identity for audit logs and budget tracking (a string id of at most 36 bytes)
scopes array of strings Permissions granted by this token (e.g. ["inference"]). Each scope is 1–64 characters from A-Z a-z 0-9 . _ : / -, at most 50 of them; a non-array value is refused
expires_at integer | null Unix expiry timestamp (seconds since epoch). null = no expiry
rate_limit object | null Per-token rate limit: {"requests": N, "window_sec": S} — requests is required, window_sec defaults to 60; no other keys
budget_usd number | null Per-token spend cap in USD as a JSON number. null = no cap

Every field is validated server-side by one shared boundary — a malformed value answers HTTP 400 naming the field and no token is created; the Users & tokens API lists the accepted and rejected shapes per field.

Token scopes

When creating a user token, select one or more scopes:

Scope Description
inference Grants access to inference endpoints. Select this for any token that makes model requests.
read Reserved for future use.
admin Reserved for future use.

Select inference for standard API access.


Creating a user

💡 Note: User creation is also covered in the Users section of the admin UI documentation. The steps below are provided here for convenience.

Screenshot: New User form in the admin UI New User form

Proceed as follows to create a user:

  1. Open Users via the user-block menu at the bottom of the left sidebar → User Management → Users.
  2. The user list opens.
  3. Click on the New User button.
  4. The New User form opens.
  5. Select the tenant from the Tenant drop-down list.
  6. Enter the email address in the Email text field.
  7. If required, enter a display name in the Name text field.
  8. Select the role from the Role drop-down list:
  9. tenant_admin — manages users and settings within the tenant
  10. member — chat and inference, plus personal authentication tokens; no administration
  11. viewer — read-only admin UI access; cannot make inference requests
  12. Click on the Create User button.

-> The user record is created and appears in the user list.

💡 Note: Platform admin users can also create other admin accounts.


Creating a token

Screenshot: New Token form for a user New Token form

Proceed as follows to create a token:

  1. Open Users via the user-block menu at the bottom of the left sidebar → User Management → Users.
  2. The user list opens.
  3. Click on the user you want to create a token for.
  4. The user detail page opens.
  5. Click on the New Token button.
  6. The New Token form opens.
  7. Select the gateway from the Gateway drop-down list.
  8. Enter a label in the Label text field.
  9. If required, enter an expiry date in the Expires At field.
  10. If required, enter a spend cap in the Budget (USD) field.
  11. If required, configure a rate limit in the Rate Limit fields.
  12. Select the required scopes under Scopes. Select inference for standard API access.
  13. Click on the Create Token button.

-> The token is created. The plaintext token is displayed once. Copy it now — it cannot be retrieved again.


Revoking a token

Proceed as follows to revoke a token:

  1. Open Users via the user-block menu at the bottom of the left sidebar → User Management → Users.
  2. The user list opens.
  3. Click on the user whose token you want to revoke.
  4. The user detail page opens, showing the token list.
  5. Click on the delete icon next to the token.

-> The token is revoked immediately. In-flight requests that have already passed the authentication phase complete normally.


Disabling authentication

⚠️ Caution: Disabling authentication removes all access control from the gateway endpoint. Any caller with network access can make inference requests and incur costs. Never disable authentication in a production environment.

Edit Gateway modal with Require auth token check box Edit Gateway modal — Require auth token check box

Proceed as follows to disable authentication on a gateway:

  1. Open Settings → Gateways (via the user-block menu at the bottom of the left sidebar → Settings).
  2. Click on the Open → button of the gateway.
  3. The gateway detail view opens.
  4. Click on the Edit button in the Gateway card header.
  5. The Edit Gateway: modal opens.
  6. Clear the Require auth token check box.
  7. Click on the Save Changes button at the bottom of the modal.

-> Authentication is disabled for the gateway. The gateway accepts inference requests without an authorization header.


API

Token and user management is also available via the Admin API. See Users & Tokens API for endpoint reference and request/response examples.

See also