Evenbead docs

Authentication and accounting firms

Every request carries one credential as a Bearer token. The database itself binds each request to that credential: a request can only see the companies the credential reaches, and the audit log records the principal behind it.

Credentials

CredentialLooks likeWho holds itLifetime
Company API keyeb_ + 43 charactersA person or an agent in one companyPeople 365 days; agents 30 days by default, at most 90
Web sessionebs_...A person signed in to the web app8 hours idle, 7 days at most, never past its key
Firm keyeb_ + 43 charactersA firm member or firm agentSame rules as company keys
Firm sessionebf_...A firm member in the accountant console8 hours idle, 7 days at most
Owner invitationebi_...The owner of a company a firm created14 days, single use

Only a hash of each secret is stored. Secrets are shown once, at creation.

curl -s https://api.evenbead.com/v1/me -H "Authorization: Bearer $EVENBEAD_KEY"

Agent identity

Agent keys must send the model on every write, and should send a run id so a run can be traced in the audit log:

  • X-Agent-Model: the model name and version, for example claude-opus-5-5.
  • X-Agent-Run-Id: your run, job or prompt id.

Over MCP, clients that cannot set headers put the same values in the request's _meta as dev.evenbead/model and dev.evenbead/run_id.

Accounting firms

Firms reach a client's books only through a grant the client's own people give (POST /v1/firm-access). The grant's scopes are the ceiling for every firm member and firm agent in that company, and the client can revoke it at any time (effective on the firm's next request).

A firm credential acts in one client per request, named by a header:

curl -s "https://api.evenbead.com/v1/proposals?status=pending" \
  -H "Authorization: Bearer $FIRM_KEY" \
  -H "X-Evenbead-Company: <client company id>"

Inside the client the firm member or agent acts as its own identity there, with every rule of that company applied: scopes, thresholds, period locks, the audit log. Over MCP, the client goes in _meta as dev.evenbead/company.

Firm-level operations (/v1/firm/...) take a firm key or firm session without the header: members, firm keys, firm agents and their per-client assignments and thresholds, the client console, bulk period locks, the firm kill switch and the firm's own audit chain.

Clients a firm creates

A firm admin can create a client company (POST /v1/firm/clients). The firm never receives a company key: it gets a single-use owner invitation to hand to the owner privately. The owner claims it in the web app at /app/claim, or with:

curl -s https://api.evenbead.com/v1/owner-invites/claim -X POST \
  -H "Authorization: Bearer ebi_..." -H "Idempotency-Key: claim-owner-001" \
  -H "Content-Type: application/json" -d '{}'

The owner key comes back once. If the claim says the invitation was already claimed, someone else used it: revoke the firm's access and contact support@evenbead.com.

Revocation and kill switches

  • Revoking a key, an agent, a session or a firm member takes effect on the next request.
  • A company's kill switch suspends every agent write in that company; a firm's kill switch suspends every firm agent's writes in every client.
  • Refused requests by a known credential are written to the audit log too.