Developer guide / Getting started

Integrate at the boundary

Perminister manages central identity and access. Consumer applications keep their own portals, sessions, data, and resource enforcement.

First integration flow

Configure storage before registration; create an administrator before assigning grants.

01

Configure private storage and an administrator

Set the Spaces endpoint, bucket, region, access key, and secret. Add an account email to PERMINISTER_ADMIN_EMAILS, then register with that address to manage identities and grants.

02

Create a central identity

Use the registration page to create an email/password account. Perminister stores a salted scrypt verifier and stable subject ID. Existing application accounts are never merged automatically.

03

Create a scoped permission grant and API key

An administrator grants generic product/project/workspace actions. Each account creates a key limited to its own grants and sees its raw secret only once.

04

Authorize each server-side resource operation

Call POST /api/authorize from trusted server code with the bearer key, scope IDs, and action. The consumer application still loads and enforces access against its own resource.

See the dashboard to create accounts and keys, and the API-key guide for the authorization payload.