Authentication#

RafikiDB has two identities:

  1. Project API key - identifies the project on /data and module routes (X-AFRIBASE-API-Key header)
  2. Project-user JWT - identifies an end-user of your app (Bearer token)

Project end-users authenticate through your app using project auth (signup / login / OTP); their JWT is what row-level security evaluates.

API keys#

Create keys under Access → API Keys. Keys are scoped:

ScopeGrants
records:readGET /data/{table}
records:writePOST / PATCH / DELETE on /data/*
storage:read / storage:writeStorage buckets/objects
env:read / env:writeEnvironment variables
secrets:read / secrets:writeSecrets
functions:read / functions:writeEdge functions
webhooks:read / webhooks:writeWebhooks
payments:read / payments:writePayments

Legacy keys with only records:* keep full module access. Keys with any module scope are restricted to exactly those scopes. Violations return 403 with an actionable message.

Headers#

X-AFRIBASE-API-Key: raf_live_xxxxxxxx
HTTP

For project end-users, the SDK sends the user JWT automatically after login:

Authorization: Bearer <project_user_jwt>
X-AFRIBASE-API-Key: raf_live_xxxxxxxx
HTTP

The data API prefers the user JWT when present, so RLS sees the logged-in user. The API key must belong to the same project.

Project user tokens#

Issued by project auth endpoints:

  • POST /projects/{id}/auth/signup
  • POST /projects/{id}/auth/signin
  • POST /projects/{id}/auth/otp/verify

They are valid per-project and used for RLS (authenticated subject).

Continue to Security (RLS + scopes).