Credentials
Octet Browser uses two credentials. Both are secrets, and neither may reach the browser.
| Credential | Looks like | Goes in | Lifetime | Issued by |
|---|---|---|---|---|
| License token | octet_live_v4.public.… |
Your edge's LICENSE setting |
365 days | Octet, by email |
| Read token | octet_read_v4.public.… |
Your backend's Authorization header |
30, 90, 180 or 365 days | You, in the Octet portal |
The license token lets your edge send sessions to Octet. The read token lets your backend fetch the verdicts for those sessions. A read token reads only the verdicts that arrived under its own license.
Get a license token
- Apply at browser.octetproof.com/signup.
- Octet reviews the application. When it is approved, Octet emails your license token and a link to the Octet portal.
- Put the token in your edge's environment as
LICENSE. See Deploy the Edge.
The license token is valid for 365 days from the day it is issued. Ask Octet for a new one before it expires, at developer@octetproof.com.
Mint a read token
- Sign in to the Octet portal at api.octetproof.com/portal/sign-in with the email address your license was issued to.
- Open your Octet Browser license and select the Read tokens tab.
- Choose a lifetime of 30, 90, 180 or 365 days. The default is 90.
- Mint the token and copy it straight into your backend's secret store. The portal shows it only once.
Only portal users with the owner or admin role can mint or revoke read tokens, and only while the license is active. A license can have at most 5 live read tokens at a time.
Rotate a read token
Because a license can hold 5 live read tokens, you can rotate with no gap:
- Mint a new read token.
- Deploy it to your backend.
- Confirm that verdict fetches succeed with the new token.
- Revoke the old token in the Read tokens tab.
Rotate before the old token expires. An expired read token gets 401 with "error": "expired".
Revoke a credential
- Read token: revoke it in the portal's Read tokens tab. Octet refuses it within minutes.
- License token: email developer@octetproof.com. Octet revokes it and issues a new one. Once the old token is revoked, your edge's requests get
401until you deploy the new one.
Keep credentials out of the browser
- Never put either token in page code, the collector's configuration, a URL, or a client-side bundle.
- Store both in your secret manager and pass them to the edge and backend as environment variables.
- Don't send tokens to Octet support. Quote the
sessionRefand the time of the request instead.