> ## Documentation Index
> Fetch the complete documentation index at: https://veryfront.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Identity and Access API

> How credentials, accounts, memberships, and resource permissions control access.

The Identity and Access API identifies callers and manages access to accounts and projects. Authentication and resource permissions answer different questions: who is calling, and what that caller can do.

## Credentials

A user session identifies a signed-in person. An API key identifies an API client within its owner's access and the key's scopes. A project-bound key is restricted to its project.

Some operations require a signed-in user and reject API keys. Each operation's reference defines its accepted credentials. The [Execution API](/docs/cloud/apis/execution#runtime-integration) explains the specialized credentials used to report and complete runtime work.

## Accounts and projects

Accounts have members and roles. Projects have their own ownership, membership, and invitation lifecycle.

Account access does not imply every permission on every project resource. Private conversations and external-service connections can impose additional access checks.

## Resource permissions

A project reference, conversation ID, or run ID selects a resource; it does not grant access. The API checks the resource involved in each request, including reads and streams.

For example, a support application may have project access while a particular conversation remains private. Parent-run relationships also do not bypass checks on child runs. For a denied request, inspect credential validity and scope as well as the caller's resource permissions.

## Invitations and ownership

Account invitations and project invitations are separate resources. Their creation, delivery, acceptance, and seat behavior follow their own contracts.

Ownership changes can require stronger authority than ordinary membership changes. The API prevents removal of the last account owner.

A support team can invite a person to its project while issuing a separate key for a backend service. The invitation and key have different lifecycles: accepting an invitation establishes membership, while a key authenticates calls under its owner and scope.

## External accounts and usage

The [Integrations API](/docs/cloud/apis/integrations) manages OAuth access to external services. API key usage and inference limits are described in the [Billing and Usage API](/docs/cloud/apis/billing-and-usage) reference.

## Get started

[Authenticate API requests](/docs/cloud/authentication) covers credential setup. [Manage project access](/docs/cloud/identity-and-access) explains invitations and service keys.

## API references

* [REST endpoints](/docs/cloud/rest/apis/identity-and-access-api)
* [GraphQL queries and mutations](/docs/cloud/graphql/apis/identity-and-access)
* [MCP tools](/docs/cloud/mcp/apis/identity-and-access)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.