Introduction

Accounts & Authentication

Sign-in, sessions, and the developer identity model

Theaimart uses a single identity for both the dashboard (interactive) and the Developer Platform (programmatic). Understanding the two token types keeps your integrations secure.

Two ways to authenticate

ContextCredentialLifetime
Dashboard / webSession JWT (issued after Google/email sign‑in)Short‑lived, auto‑refreshed
Developer Platform / CIAPI key (Bearer token)Long‑lived, revocable

Interactive sign‑in

Sign in with Google or email. Behind the scenes the platform verifies your identity and issues a session token that authorizes dashboard requests. You never handle this token directly.

Programmatic access

For scripts, CI, and server‑to‑server calls, create an API key under Dashboard → Developer Platform → API Keys and send it as a bearer token:

curl https://api.theaimart.co/api/v1/apps \
  -H "Authorization: Bearer $THEAIMART_API_KEY"

Treat API keys like passwords. Never commit them to source control or ship them in a client bundle. Store them in environment variables or a secrets manager, and rotate on a schedule — see API Keys.

Scopes & least privilege

API keys are scoped. Grant a key only the permissions it needs:

  • •listings:read — read your apps, web apps, and agents
  • •listings:write — create and update listings
  • •releases:write — publish releases
  • •webhooks:manage — manage webhook subscriptions
  • •analytics:read — read metrics

A CI key that only publishes releases needs releases:write — nothing more.

The developer identity

Your public developer page (theaimart.co/developers/<id>) aggregates your listings, badges, and reputation. Buyers use it to judge trust, so keep your profile complete and pursue verification.

Next