For AI agents: this page is also available as Markdown at https://docs.refabric.com/setting-up/accounts-and-identity.md, and the index of every page is https://docs.refabric.com/llms.txt.

Setting Up

Accounts and identity

Who you sign in as, which account your API keys act for, and what belongs to that account.

You sign in to the Refabric app as a person. Your API keys act for your account: every job, file, record and credit they touch is that account's. Your keys act for the account you sign in to.

Your login and your API keys are not the same thing. Signing in opens the app and its Developers screens (Panel › Developers › Overview); a key calls the public API from your server; sign-in is for the app (Authentication).

How it works

  • You sign in to the Refabric app. Keys are created there, in Panel › Developers › Keys.
  • A key is owned by the user who created it and acts as that user: it spends that user's credits, and the files it uploads or produces are that user's (Authentication).
  • A key's scopes define what it may do, within its user's permissions.

Sign in

The app's sign-in page offers e-mail and password, Google, and single sign-on (SSO) for organisations that have it set up for their e-mail domain.

Account types

What your account may do is set by its plan:

  • API access depends on your plan; without it a key is answered 403 api_access_not_included (Authentication).
  • A task your plan does not allow answers 403 permission_denied.
  • Trial accounts receive watermarked images (Files).

Everything belongs to the account

WhatBelongs to
Jobs started with your keysyour account; GET /v1/jobs lists them
Files you upload and files your jobs produceyour account; you see them in the app too
Records (moodboards, fabrics, brand kits, range plans)your account
Creditsyour account's balance (Pricing)
API keysthe user who created them
Webhook endpoints and the request logyour account (Panel › Developers › Webhooks, Panel › Developers › Request log)

Jobs you start in the Refabric app are yours too, but they are not sent to your registered webhook endpoints and not written to the request log (Webhooks).