Developer guide

Build with Perminister

Perminister provides central identities, password credentials, sessions, scoped permissions, and API keys. Consumer applications keep their branded portals, app-local sessions, domain data, and resource enforcement.

Available now: account and key management in the dashboard, GET /api/auth/session for a browser session, and POST /api/authorize for bearer-key checks. GET /api/health reports process liveness only.

Choose a guide

Each section covers current behavior and the configuration it needs.

Implemented service boundary

Perminister stores identity and access state; consumer applications own their domain data and final resource checks.

  • Email/password accounts and revocable browser sessions
  • Administrator-managed generic product/project/workspace grants
  • API-key lifecycle with one-time secret display
  • Private DigitalOcean Spaces records and recoverable event snapshots