Appearance
Credentials
Credentials let apps, agents and CI jobs talk to Shaep's APIs. Manage them from Settings > Credentials.
Kinds of Credentials
The page has three tabs, one per kind:
| Tab | Client ID prefix | Secret | Use it for |
|---|---|---|---|
| App Credentials | svc_ | Yes, shown once | Servers and apps calling Shaep APIs, CI logins, writing audit events |
| Agents | agent_ | Yes, shown once | AI agents that talk to people through channels (Work, Signal, email), or an editor that runs as the agent |
| Managed Identities | mi_ | No | Referenced from Settings > Secrets or an editor's "Run as"; Shaep hands out short-lived tokens for it, so there is no secret to store |
Settings > My Agents is for agents that act as you. Any member can create one for themselves, bounded to their own permissions. They have no secret: an editor uses one through "Run as".
Creating a Credential
Owners and admins create credentials:
- Open Settings > Credentials and pick the tab for the kind you need
- Click Create App Credential, Create Agent or Create Managed Identity
- Enter a name
- Choose the permissions: pick a preset under Quick setup, or Customize scopes (advanced)
- Optionally change Expiration under Advanced options: 30 days, 90 days, 1 year or no expiration. App credentials and agents default to 90 days, managed identities to no expiration
- Click Create
For app credentials and agents, a dialog shows the Client ID and Client Secret.
WARNING
The Client Secret is shown only once and cannot be retrieved or rotated later. If it is lost, create a new credential, switch your app to it, and revoke the old one.
You cannot grant permissions your own role does not have. Only owners can create credentials with the Audit trail preset.
Presets
| Preset | Tab | Grants |
|---|---|---|
| Deployed agent | Agents | Channels (lobby) and platform AI models |
| Coding agent | Agents | Deployed agent, plus code, CI, apps and deployments |
| Manage groups & channels | Agents | Listing and binding its own channels |
| Push & pull images | App Credentials, Managed Identities | Container registry push and pull |
| Deploy & manage apps | App Credentials, Managed Identities | Code, apps, deployments and CI |
| CI runner | App Credentials, Managed Identities | Registry and deployments, for CI/CD |
| Full dev access | App Credentials, Managed Identities | Code, registry, apps, deployments and CI |
| AI models | App Credentials, Managed Identities | Platform AI models |
| Audit trail | App Credentials, Managed Identities | Reading and writing the audit trail (owner only) |
| Read-only | All tabs | Viewing apps, deployments, CI runs, storage and models |
Using a Credential
Exchange the client ID and secret for an access token:
bash
curl -X POST "https://auth.nextepoch.cloud/oauth/token" \
-u "<client_id>:<client_secret>" \
-d "grant_type=client_credentials"Use the returned access_token in the Authorization: Bearer <token> header. Tokens are short-lived and there is no refresh token: request a new one before expires_in runs out. Scopes you ask for that the credential does not hold are left out of the token, so check the returned scope.
Expiry and Revoking
- App credentials and agents expire after 90 days unless you chose otherwise; managed identities do not expire unless you chose a date. An expired credential gets
401 invalid_client; check the Expires column. - An expired managed identity can no longer be referenced from a new secret or used for "Run as". CI skips an existing secret whose managed identity has expired, so replace the identity before its date passes.
- Revoke stops a credential from getting new tokens immediately. Tokens it already received stay valid until they expire: usually within 15 minutes, longer only for a CI job that is already running. An agent's open connection ends when its token expires.
- A revoked credential can then be deleted permanently.
Revoking and deleting ask you to sign in again before they run.
Credentials in CI
For CI, reference a managed identity from Settings > Secrets instead of storing a secret: choose Reference a managed identity and a binding:
| Binding | Injects |
|---|---|
| Registry (docker login) | REGISTRY_USERNAME and REGISTRY_PASSWORD |
| Platform token | NEXTEPOCH_TOKEN |
| Custom variable | A token in a variable with the secret's name |
Every organization's CI starts with a managed identity called CI registry and a REGISTRY_LOGIN secret that uses it, so images can be pushed without any setup.
Webhooks
Shaep does not send or manage webhooks: there is no webhooks page, and the platform does not call your URLs when something happens. To receive webhooks from another service (Stripe, GitHub, a payment provider) in your app, the endpoint must be reachable without platform sign-in, for example a public deployment, and your app must verify the sender's signature itself.
Next Steps
- Deploy an app that uses your credentials
- Configure access control for your deployments