Security model
Authentication
An API credential identifies one approved developer application. It does not grant unrestricted customer access. Every protected route also enforces declared scope and resource ownership boundaries.
Bearer credential
Authorization: Bearer az_live_<prefix>.<secret>
Keep the full credential in trusted server-side secret storage. Never ship it in browser JavaScript, mobile bundles, source control or support email.
Signed consequential requests
| Header | Purpose |
|---|---|
Idempotency-Key |
Stable identity for one logical write. |
X-Azari-Timestamp |
Signing timestamp. |
X-Azari-Nonce |
Replay-resistant nonce. |
X-Azari-Signature |
Application signature for governed write routes. |
Sandbox authentication
The browser simulator injects a public documentation-only sandbox marker. Code samples
show Bearer <sandbox-demo-token> as a placeholder. It is not a
production credential and is rejected outside the simulated environment.