Worlds separates management credentials from world data credentials. Treat them
as different secrets with different blast radii.
Authentication strategies
The platform uses separate token kinds depending on the use case.
Platform tokens use the wzp_ prefix. They authenticate management operations
against the Wazoo Platform API, including user-owned World
metadata, platform tokens, world auth tokens, and usage records.
Include the token in the Authorization header:
World tokens
World tokens use the wzw_ prefix. They are data-plane credentials for access
to specific worlds. Agents and applications should use world tokens when they
query or update graph data. Create and revoke them from the
Console.
Store world tokens separately from platform tokens. A world token should not be
able to manage platform metadata or mint new platform credentials.
World token rotation is revoke-and-replace. The rotation operation revokes the
existing World tokens and returns one replacement token once; it must not expand
the active token count or access duration when a World is throttled.
Admin platform tokens are global operator credentials for private-beta support.
They are manually seeded, never created through public token endpoints, and must
use kind = "ADMIN", user_uid = NULL, and include the admin scope.
Admin-only operations and quota bypasses write internal audit events. There is
no public audit log API in v1.
Identity service
The Console is the human-facing control surface for Wazoo. Identity and team
management are separate from bearer tokens used by APIs and agents.
Tenant isolation
The platform enforces resource boundaries at the user and World level. The
current Platform API stores management metadata separately from world graph
data.
- Platform boundary: Platform tokens manage metadata and credentials.
- World boundary: World tokens authorize data-plane access to specific
worlds.
- Resource boundary: Applications should only receive the narrowest token
needed for the task.
Local development
Local and self-hosted deployments may use different authentication settings
while they are being developed. Do not expose a deployment publicly unless token
validation is enabled and secrets are stored outside source control.
Never commit platform tokens, world tokens, database credentials, or tunnel
credentials. Rotate any token that appears in logs, source control,
screenshots, or shared chat transcripts.