Authentication
API authentication
Authentication
Authenticate with the Grayscale API for integrations and plugins.
Overview
Grayscale uses Bearer JWT authentication. All API routes are company-scoped — tenant isolation is enforced by the Company Guard on every request.
Obtain a Token
curl -X POST http://localhost:4000/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"founder@example.com","password":"your-password"}'
Response includes a JWT access token.
Use the Token
curl http://localhost:4000/companies/{companyId}/mission-control/health \
-H "Authorization: Bearer <token>"
Replace {companyId} with your organization ID from the session or dashboard.
Integration Authentication
Plugins and connectors use the Integration Credential Vault:
- Register integration via Integration API
- Store credentials in company-scoped vault
- Connector runs in sandbox until certified
- Policy Engine evaluates automated actions
See Plugin Development and Webhooks.
Enterprise SSO
Single Sign-On (SAML/OIDC) is available on Enterprise plans. Contact sales@projectgrayscale.com.
Security Practices
- Rotate JWT secrets in production
- Never embed tokens in client-side code
- Use HTTPS in all non-local environments
- Scope integrations to minimum required permissions
