Acting as —.
Team access is being verified. Until then, treat this workspace as read-only.
Before you can mint API keys or create sessions, please review and accept the following:
HMAC-SHA256-signed event delivery · 5-minute timestamp tolerance
Webhook endpoints
Subscribe to session lifecycle, egress, challenge, profile-save,
payment, and key-revocation events. Each endpoint gets
its own signing secret; verify with the SDK's
verifyWebhookSignature helper.
Failed deliveries retry 5× with exponential backoff before landing in the DLQ. DLQ entries are admin-replayable; no auto-retry past the initial attempts to avoid storm-on-recovery patterns.