[{"data":1,"prerenderedAt":430},["ShallowReactive",2],{"docs-page:\u002Fdocs\u002Fauthentication":3,"docs-navigation-links":398},{"id":4,"title":5,"body":6,"description":390,"extension":391,"meta":392,"navigation":393,"path":394,"seo":395,"stem":396,"__hash__":397},"docs\u002Fdocs\u002Fauthentication.md","Authentication",{"type":7,"value":8,"toc":384},"minimark",[9,14,18,35,42,45,49,56,59,141,148,152,155,171,217,223,246,253,257,260,269,292,373,380],[10,11,13],"h2",{"id":12},"team-api-keys","Team API keys",[15,16,17],"p",{},"Authenticated endpoints use a bearer token:",[19,20,25],"pre",{"className":21,"code":22,"language":23,"meta":24,"style":24},"language-http shiki shiki-themes github-dark","Authorization: Bearer \u003Cepho_api_key>\n","http","",[26,27,28],"code",{"__ignoreMap":24},[29,30,33],"span",{"class":31,"line":32},"line",1,[29,34,22],{},[15,36,37,38,41],{},"An API key belongs to a team rather than an individual user. Every chat lookup,\nturn lookup, cancellation, and credit read is scoped to that team. A valid key\ncannot see another team's resources; foreign identifiers return ",[26,39,40],{},"404",".",[15,43,44],{},"Create and revoke keys from the Epho application. Plain-text keys are displayed\nonly once when they are minted.",[10,46,48],{"id":47},"provider-api-keys","Provider API keys",[15,50,51,52,55],{},"The ",[26,53,54],{},"provider_api_key"," in a run request is not the same credential as the Epho\nbearer token.",[15,57,58],{},"Epho derives the provider from the selected harness and model, then passes the\nopaque key to that provider through the sandbox runner:",[60,61,62,75],"table",{},[63,64,65],"thead",{},[66,67,68,72],"tr",{},[69,70,71],"th",{},"Harness and model",[69,73,74],{},"Key is routed to",[76,77,78,93,106,118,129],"tbody",{},[66,79,80,90],{},[81,82,83,86,87],"td",{},[26,84,85],{},"codex"," + ",[26,88,89],{},"gpt-*",[81,91,92],{},"OpenAI",[66,94,95,103],{},[81,96,97,86,100],{},[26,98,99],{},"claude",[26,101,102],{},"claude-*",[81,104,105],{},"Anthropic",[66,107,108,116],{},[81,109,110,86,113],{},[26,111,112],{},"opencode",[26,114,115],{},"openai\u002F*",[81,117,92],{},[66,119,120,127],{},[81,121,122,86,124],{},[26,123,112],{},[26,125,126],{},"anthropic\u002F*",[81,128,105],{},[66,130,131,138],{},[81,132,133,86,135],{},[26,134,112],{},[26,136,137],{},"opencode\u002F*",[81,139,140],{},"OpenCode Zen",[15,142,143,144,147],{},"Supply the provider key on every paid run, including resumed chats. Free\nOpenCode Zen models ending in ",[26,145,146],{},"-free"," are the only runs that do not require one.",[10,149,151],{"id":150},"headless-email-signup","Headless email signup",[15,153,154],{},"Clients without an existing account can create one through:",[19,156,158],{"className":21,"code":157,"language":23,"meta":24,"style":24},"POST \u002Fapi\u002Fv1\u002Fsignup\nContent-Type: application\u002Fjson\n",[26,159,160,165],{"__ignoreMap":24},[29,161,162],{"class":31,"line":32},[29,163,164],{},"POST \u002Fapi\u002Fv1\u002Fsignup\n",[29,166,168],{"class":31,"line":167},2,[29,169,170],{},"Content-Type: application\u002Fjson\n",[19,172,176],{"className":173,"code":174,"language":175,"meta":24,"style":24},"language-json shiki shiki-themes github-dark","{\n  \"username\": \"ada@example.com\",\n  \"password\": \"a-strong-password\"\n}\n","json",[26,177,178,184,200,211],{"__ignoreMap":24},[29,179,180],{"class":31,"line":32},[29,181,183],{"class":182},"s95oV","{\n",[29,185,186,190,193,197],{"class":31,"line":167},[29,187,189],{"class":188},"sDLfK","  \"username\"",[29,191,192],{"class":182},": ",[29,194,196],{"class":195},"sU2Wk","\"ada@example.com\"",[29,198,199],{"class":182},",\n",[29,201,203,206,208],{"class":31,"line":202},3,[29,204,205],{"class":188},"  \"password\"",[29,207,192],{"class":182},[29,209,210],{"class":195},"\"a-strong-password\"\n",[29,212,214],{"class":31,"line":213},4,[29,215,216],{"class":182},"}\n",[15,218,219,222],{},[26,220,221],{},"username"," must be an email address. A successful request creates a user,\npersonal team, and team-scoped key:",[19,224,226],{"className":173,"code":225,"language":175,"meta":24,"style":24},"{\n  \"api_key\": \"1|...\"\n}\n",[26,227,228,232,242],{"__ignoreMap":24},[29,229,230],{"class":31,"line":32},[29,231,183],{"class":182},[29,233,234,237,239],{"class":31,"line":167},[29,235,236],{"class":188},"  \"api_key\"",[29,238,192],{"class":182},[29,240,241],{"class":195},"\"1|...\"\n",[29,243,244],{"class":31,"line":202},[29,245,216],{"class":182},[15,247,248,249,252],{},"The endpoint returns ",[26,250,251],{},"201",", shows the key once, and is limited to three requests\nper IP per minute.",[10,254,256],{"id":255},"device-oauth-signup","Device OAuth signup",[15,258,259],{},"Headless clients can also use Google or GitHub:",[19,261,263],{"className":21,"code":262,"language":23,"meta":24,"style":24},"POST \u002Fapi\u002Fv1\u002Fsignup\u002Fgoogle\n",[26,264,265],{"__ignoreMap":24},[29,266,267],{"class":31,"line":32},[29,268,262],{},[15,270,51,271,273,274,277,278,277,281,199,284,287,288,291],{},[26,272,251],{}," response includes an ",[26,275,276],{},"authorization_url",", ",[26,279,280],{},"ticket",[26,282,283],{},"poll_secret",[26,285,286],{},"poll_url",", and ",[26,289,290],{},"expires_in",". The ticket lives for 600 seconds.",[293,294,295,302,317,323],"ol",{},[296,297,298,299,301],"li",{},"Open ",[26,300,276],{}," in the user's browser.",[296,303,304,305,307,308],{},"Poll ",[26,306,286],{}," with the secret:",[19,309,311],{"className":21,"code":310,"language":23,"meta":24,"style":24},"X-Device-Secret: \u003Cpoll_secret>\n",[26,312,313],{"__ignoreMap":24},[29,314,315],{"class":31,"line":32},[29,316,310],{},[296,318,319,320,41],{},"Continue while the response is ",[26,321,322],{},"{\"status\":\"pending\"}",[296,324,325,326],{},"A completed response returns the API key and consumes the ticket:",[19,327,329],{"className":173,"code":328,"language":175,"meta":24,"style":24},"{\n  \"status\": \"complete\",\n  \"api_key\": \"1|...\",\n  \"is_new_user\": true\n}\n",[26,330,331,335,347,358,368],{"__ignoreMap":24},[29,332,333],{"class":31,"line":32},[29,334,183],{"class":182},[29,336,337,340,342,345],{"class":31,"line":167},[29,338,339],{"class":188},"  \"status\"",[29,341,192],{"class":182},[29,343,344],{"class":195},"\"complete\"",[29,346,199],{"class":182},[29,348,349,351,353,356],{"class":31,"line":202},[29,350,236],{"class":188},[29,352,192],{"class":182},[29,354,355],{"class":195},"\"1|...\"",[29,357,199],{"class":182},[29,359,360,363,365],{"class":31,"line":213},[29,361,362],{"class":188},"  \"is_new_user\"",[29,364,192],{"class":182},[29,366,367],{"class":188},"true\n",[29,369,371],{"class":31,"line":370},5,[29,372,216],{"class":182},[15,374,375,376,379],{},"The poll secret may alternatively be provided as the ",[26,377,378],{},"secret"," query parameter.\nThe API key cannot be retrieved from the same ticket twice.",[381,382,383],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .s95oV, html code.shiki .s95oV{--shiki-default:#E1E4E8}html pre.shiki code .sDLfK, html code.shiki .sDLfK{--shiki-default:#79B8FF}html pre.shiki code .sU2Wk, html code.shiki .sU2Wk{--shiki-default:#9ECBFF}",{"title":24,"searchDepth":167,"depth":167,"links":385},[386,387,388,389],{"id":12,"depth":167,"text":13},{"id":47,"depth":167,"text":48},{"id":150,"depth":167,"text":151},{"id":255,"depth":167,"text":256},"Team-scoped API keys, provider credentials, and headless signup flows.","md",{},true,"\u002Fdocs\u002Fauthentication",{"title":5,"description":390},"docs\u002Fauthentication","KaQk3v-T3wWb4u6fwqb7ZeECPLayiK752xwV3x__3Dk",[399,402,403,406,409,412,415,418,421,424,427],{"path":400,"title":401},"\u002Fdocs","Overview",{"path":394,"title":5},{"path":404,"title":405},"\u002Fdocs\u002Fchats-and-turns","Chats and turns",{"path":407,"title":408},"\u002Fdocs\u002Ferrors","Errors and statuses",{"path":410,"title":411},"\u002Fdocs\u002Ffiles-and-repositories","Files and repositories",{"path":413,"title":414},"\u002Fdocs\u002Fharnesses-and-models","Harnesses and models",{"path":416,"title":417},"\u002Fdocs\u002Fmcp-and-environment","MCP and environment",{"path":419,"title":420},"\u002Fdocs\u002Fquickstart","Quickstart",{"path":422,"title":423},"\u002Fdocs\u002Fresources-and-billing","Resources and billing",{"path":425,"title":426},"\u002Fdocs\u002Fresuming-chats","Resuming chats",{"path":428,"title":429},"\u002Fdocs\u002Frunning-agents","Running agents",1785310516452]