Authentication#
RafikiDB has two identities:
- Project API key - identifies the project on
/dataand module routes (X-AFRIBASE-API-Keyheader) - Project-user JWT - identifies an end-user of your app (Bearer token)
Project end-users authenticate through your app using project auth (signup / login / OTP); their JWT is what row-level security evaluates.
API keys#
Create keys under Access → API Keys. Keys are scoped:
| Scope | Grants |
|---|---|
records:read | GET /data/{table} |
records:write | POST / PATCH / DELETE on /data/* |
storage:read / storage:write | Storage buckets/objects |
env:read / env:write | Environment variables |
secrets:read / secrets:write | Secrets |
functions:read / functions:write | Edge functions |
webhooks:read / webhooks:write | Webhooks |
payments:read / payments:write | Payments |
Legacy keys with only records:* keep full module access. Keys with any
module scope are restricted to exactly those scopes. Violations return 403
with an actionable message.
Headers#
X-AFRIBASE-API-Key: raf_live_xxxxxxxx
HTTPFor project end-users, the SDK sends the user JWT automatically after login:
Authorization: Bearer <project_user_jwt>
X-AFRIBASE-API-Key: raf_live_xxxxxxxx
HTTPThe data API prefers the user JWT when present, so RLS sees the logged-in user. The API key must belong to the same project.
Project user tokens#
Issued by project auth endpoints:
POST /projects/{id}/auth/signupPOST /projects/{id}/auth/signinPOST /projects/{id}/auth/otp/verify
They are valid per-project and used for RLS (authenticated subject).
Continue to Security (RLS + scopes).