Console¶
Vendor work that is not the check API lives at e10s.io. Your login persists across tabs in the same browser.
Members¶
People on your team are members. Signed-in humans use the console. Automation uses a service-account key.
Each member, and each service account, has a role:
| Role | Can |
|---|---|
| admin | Everything: members, invites, service accounts, keys, organization settings, the audit log, deleting the organization. Whoever creates the organization is an admin. |
| developer | Features, plans, subscribers, the webhook, and check. Sees the organization, members, and service accounts, but can't change them or see invites. |
| viewer | Sees what a developer sees. Changes nothing. |
| runtime | Check only. For service accounts on production servers. |
Invites and Add by user_id default to viewer. New service accounts default to runtime.
Members → change someone's role or status (active or suspended), or remove them. A service account's role is on the Service accounts page. An admin can give any role, including admin, so make admins only of people you'd trust with the whole organization. An organization always keeps at least one admin.
Create a member key¶
Service accounts → Create key. Name the key. It does what the service account's role allows, and follows the role if it changes. For a check-only production key, use a runtime service account.
Copy the plaintext once. What each role allows: Authentication.
Invites¶
Members → copy invite link. Production links look like https://e10s.io/invites?invite=….
The link is a shareable join token, not bound to an email. Anyone who opens it and signs in joins the organization.
While the invite is active, the list includes the token. Copy the same link again from that row.
Redeem happens after sign-in. Unknown tokens are 404. Already used, revoked, or expired tokens are 409.
Webhooks¶
Settings → Webhooks. One URL per organization (http or https).
The signing secret is shown once on create and on rotate (e10s-wh-1-…). Store it; the console then shows only a prefix. Rotate if the secret leaks. Rotation is immediate: the old secret stops working right away, with no overlap. Changing the URL keeps the current secret.
Receiving, verifying, retries, and disable: Webhooks. Event JSON: Webhooks.
Audit log¶
Settings → Audit log (admins only). Who changed what, newest first: one row per change made in the console or with a key, with who sent it, from which key or session and IP, what changed, and how it ended. Filter by member or by result.
Reads and checks aren't recorded. Fields, outcomes, and the API: Audit log.