Developer Architecture

How the pieces fit together: you manage resources in the Portal, and your key unlocks the Public API for both the CLI and the Playground.

The big picture

text
Developer
   │  signs in (JWT session)
   ▼
Developer Portal ──────────────► Management API  (/api/platform/*, JWT)
   │  creates                         manages workspaces, projects, keys
   ▼
Workspace
   │  contains
   ▼
Project
   │  issues
   ▼
API Key  (carrier_sk_… / carrier_pk_…)
   │  authenticates
   ▼
Carrier OS Public API  (/v1/*, Bearer API key)
   ▲                        ▲
   │                        │
  CLI                   Playground
 (cos / carrieros)     (dashboard tester)

Two API surfaces

  • Management API — /api/platform/*, authenticated by your dashboard login (JWT). Creates and manages workspaces, projects, and keys. Not for application traffic.
  • Public API — /v1/*, authenticated by an API key (Authorization: Bearer carrier_sk_…). This is what the CLI, the Playground, and your code all call.

Scope inheritance

Each layer inherits from the one above it. A key belongs to exactly one project, and every request made with that key is automatically scoped to its workspace and project — a key can never touch another project's data.

text
Workspace
   └── Project
         └── API Key
               └── Requests (scoped automatically)
The CLI and the Playground are just two clients of the same Public API. Anything one can do, your own code can do with the same key and endpoints — see the API Reference.