Skip to content

Credentials ​

Credentials let apps, agents and CI jobs talk to Shaep's APIs. Manage them from Settings > Credentials.

Kinds of Credentials ​

The page has three tabs, one per kind:

TabClient ID prefixSecretUse it for
App Credentialssvc_Yes, shown onceServers and apps calling Shaep APIs, CI logins, writing audit events
Agentsagent_Yes, shown onceAI agents that talk to people through channels (Work, Signal, email), or an editor that runs as the agent
Managed Identitiesmi_NoReferenced from Settings > Secrets or an editor's "Run as"; Shaep hands out short-lived tokens for it, so there is no secret to store

Settings > My Agents is for agents that act as you. Any member can create one for themselves, bounded to their own permissions. They have no secret: an editor uses one through "Run as".

Creating a Credential ​

Owners and admins create credentials:

  1. Open Settings > Credentials and pick the tab for the kind you need
  2. Click Create App Credential, Create Agent or Create Managed Identity
  3. Enter a name
  4. Choose the permissions: pick a preset under Quick setup, or Customize scopes (advanced)
  5. Optionally change Expiration under Advanced options: 30 days, 90 days, 1 year or no expiration. App credentials and agents default to 90 days, managed identities to no expiration
  6. Click Create

For app credentials and agents, a dialog shows the Client ID and Client Secret.

WARNING

The Client Secret is shown only once and cannot be retrieved or rotated later. If it is lost, create a new credential, switch your app to it, and revoke the old one.

You cannot grant permissions your own role does not have. Only owners can create credentials with the Audit trail preset.

Presets ​

PresetTabGrants
Deployed agentAgentsChannels (lobby) and platform AI models
Coding agentAgentsDeployed agent, plus code, CI, apps and deployments
Manage groups & channelsAgentsListing and binding its own channels
Push & pull imagesApp Credentials, Managed IdentitiesContainer registry push and pull
Deploy & manage appsApp Credentials, Managed IdentitiesCode, apps, deployments and CI
CI runnerApp Credentials, Managed IdentitiesRegistry and deployments, for CI/CD
Full dev accessApp Credentials, Managed IdentitiesCode, registry, apps, deployments and CI
AI modelsApp Credentials, Managed IdentitiesPlatform AI models
Audit trailApp Credentials, Managed IdentitiesReading and writing the audit trail (owner only)
Read-onlyAll tabsViewing apps, deployments, CI runs, storage and models

Using a Credential ​

Exchange the client ID and secret for an access token:

bash
curl -X POST "https://auth.nextepoch.cloud/oauth/token" \
  -u "<client_id>:<client_secret>" \
  -d "grant_type=client_credentials"

Use the returned access_token in the Authorization: Bearer <token> header. Tokens are short-lived and there is no refresh token: request a new one before expires_in runs out. Scopes you ask for that the credential does not hold are left out of the token, so check the returned scope.

Expiry and Revoking ​

  • App credentials and agents expire after 90 days unless you chose otherwise; managed identities do not expire unless you chose a date. An expired credential gets 401 invalid_client; check the Expires column.
  • An expired managed identity can no longer be referenced from a new secret or used for "Run as". CI skips an existing secret whose managed identity has expired, so replace the identity before its date passes.
  • Revoke stops a credential from getting new tokens immediately. Tokens it already received stay valid until they expire: usually within 15 minutes, longer only for a CI job that is already running. An agent's open connection ends when its token expires.
  • A revoked credential can then be deleted permanently.

Revoking and deleting ask you to sign in again before they run.

Credentials in CI ​

For CI, reference a managed identity from Settings > Secrets instead of storing a secret: choose Reference a managed identity and a binding:

BindingInjects
Registry (docker login)REGISTRY_USERNAME and REGISTRY_PASSWORD
Platform tokenNEXTEPOCH_TOKEN
Custom variableA token in a variable with the secret's name

Every organization's CI starts with a managed identity called CI registry and a REGISTRY_LOGIN secret that uses it, so images can be pushed without any setup.

Webhooks ​

Shaep does not send or manage webhooks: there is no webhooks page, and the platform does not call your URLs when something happens. To receive webhooks from another service (Stripe, GitHub, a payment provider) in your app, the endpoint must be reachable without platform sign-in, for example a public deployment, and your app must verify the sender's signature itself.

Next Steps ​

Shaep Documentation