Security
Authentication and access control
Manage team access and API authentication for compos projects.
Team roles
Roles are defined in the data model but **are not enforced yet**. The membership records carry a role, and the API returns your organizations, but no endpoint authorizes on it and there is no UI for assigning roles. Until enforcement ships, every member of an organization has the same access to that organization's projects. This page will be updated when it does.
API authentication
All API requests require a personal access token or project-scoped API key:
curl -H "Authorization: Bearer compos_sk_..." https://api.compos.com/v1/deploymentsAudit logging
Administrative actions are logged with timestamps and user identity. Audit logs are available via the dashboard and the API.