Desvy SPP2 PlatformSemantic Evidence Infrastructure

Authentication

Two separate authentication mechanisms, used for two separate surfaces — never mixed:

  • Browser (web UI) — session cookie, HttpOnly, Secure, SameSite=Lax. Every state-changing form submission requires a CSRF token embedded in the page.
  • API (Gateway) — Bearer token in the Authorization header: Authorization: Bearer sk_live_.... Never a query parameter. No CSRF token is required or accepted for API-key-authenticated requests — a bearer token is not an ambient browser credential, so it is not subject to CSRF by construction.

API keys are created from the web UI (API Keys page), shown exactly once at creation, and can be revoked immediately at any time. A revoked key stops working on its very next request.

↑