All docs

Security

Authentication and access control

Manage team access and API authentication for compos projects.

Team roles

Roles are defined in the data model but **are not enforced yet**. The membership records carry a role, and the API returns your organizations, but no endpoint authorizes on it and there is no UI for assigning roles. Until enforcement ships, every member of an organization has the same access to that organization's projects. This page will be updated when it does.

API authentication

All API requests require a personal access token or project-scoped API key:

bash
curl -H "Authorization: Bearer compos_sk_..." https://api.compos.com/v1/deployments

Audit logging

Administrative actions are logged with timestamps and user identity. Audit logs are available via the dashboard and the API.