Docs/Octet Browser/Guides/Credentials

Credentials

Octet Browser uses two credentials. Both are secrets, and neither may reach the browser.

Credential Looks like Goes in Lifetime Issued by
License token octet_live_v4.public.… Your edge's LICENSE setting 365 days Octet, by email
Read token octet_read_v4.public.… Your backend's Authorization header 30, 90, 180 or 365 days You, in the Octet portal

The license token lets your edge send sessions to Octet. The read token lets your backend fetch the verdicts for those sessions. A read token reads only the verdicts that arrived under its own license.

Get a license token

  1. Apply at browser.octetproof.com/signup.
  2. Octet reviews the application. When it is approved, Octet emails your license token and a link to the Octet portal.
  3. Put the token in your edge's environment as LICENSE. See Deploy the Edge.

The license token is valid for 365 days from the day it is issued. Ask Octet for a new one before it expires, at developer@octetproof.com.

Mint a read token

  1. Sign in to the Octet portal at api.octetproof.com/portal/sign-in with the email address your license was issued to.
  2. Open your Octet Browser license and select the Read tokens tab.
  3. Choose a lifetime of 30, 90, 180 or 365 days. The default is 90.
  4. Mint the token and copy it straight into your backend's secret store. The portal shows it only once.

Only portal users with the owner or admin role can mint or revoke read tokens, and only while the license is active. A license can have at most 5 live read tokens at a time.

Rotate a read token

Because a license can hold 5 live read tokens, you can rotate with no gap:

  1. Mint a new read token.
  2. Deploy it to your backend.
  3. Confirm that verdict fetches succeed with the new token.
  4. Revoke the old token in the Read tokens tab.

Rotate before the old token expires. An expired read token gets 401 with "error": "expired".

Revoke a credential

  • Read token: revoke it in the portal's Read tokens tab. Octet refuses it within minutes.
  • License token: email developer@octetproof.com. Octet revokes it and issues a new one. Once the old token is revoked, your edge's requests get 401 until you deploy the new one.

Keep credentials out of the browser

  • Never put either token in page code, the collector's configuration, a URL, or a client-side bundle.
  • Store both in your secret manager and pass them to the edge and backend as environment variables.
  • Don't send tokens to Octet support. Quote the sessionRef and the time of the request instead.