Authentication #
HeySora separates three kinds of callers.
Staff #
People sign in at app.heysora.ai with email and password. The session cookie is host-only to the app host, is HttpOnly and Secure, and is never sent to the API or documentation hosts. Roles decide what each person can do inside an organisation.
Your backend #
Server-to-server calls to the machine API use connection credentials: a bearer token plus a request signature, with a short validity window and replay protection. Credentials belong to one connection of one organisation and can be rotated. The algorithm, the signature version and code samples are maintained in one place: Authentication and request signing (sign-in required).
Your customers #
End customers never receive your server credentials. Your backend mints a short-lived customer session and gives it to the SDK or the web chat; it can be refreshed and revoked.
Related: API quick start, security basics.