Introduction
Accounts & Authentication
Sign-in, sessions, and the developer identity model
Theaimart uses a single identity for both the dashboard (interactive) and the Developer Platform (programmatic). Understanding the two token types keeps your integrations secure.
Two ways to authenticate
| Context | Credential | Lifetime |
|---|---|---|
| Dashboard / web | Session JWT (issued after Google/email sign‑in) | Short‑lived, auto‑refreshed |
| Developer Platform / CI | API key (Bearer token) | Long‑lived, revocable |
Interactive sign‑in
Sign in with Google or email. Behind the scenes the platform verifies your identity and issues a session token that authorizes dashboard requests. You never handle this token directly.
Programmatic access
For scripts, CI, and server‑to‑server calls, create an API key under Dashboard → Developer Platform → API Keys and send it as a bearer token:
curl https://api.theaimart.co/api/v1/apps \
-H "Authorization: Bearer $THEAIMART_API_KEY"
Treat API keys like passwords. Never commit them to source control or ship them in a client bundle. Store them in environment variables or a secrets manager, and rotate on a schedule — see API Keys.
Scopes & least privilege
API keys are scoped. Grant a key only the permissions it needs:
- •
listings:read— read your apps, web apps, and agents - •
listings:write— create and update listings - •
releases:write— publish releases - •
webhooks:manage— manage webhook subscriptions - •
analytics:read— read metrics
A CI key that only publishes releases needs releases:write — nothing more.
The developer identity
Your public developer page (theaimart.co/developers/<id>) aggregates your listings, badges, and reputation. Buyers use it to judge trust, so keep your profile complete and pursue verification.