• Platform
  • Solutions
  • Developers
  • Showcase
  • Pricing
  • Company
Get Started
  • Platform

    • Overview
    • Conductor
    • Architecture
    • Security
    • Status

    Capabilities

    • All 276
    • AI & ML
    • Storage
    • Auth & Identity
    • Billing
    • Search
    • Compute
    • Media

    SDK

    • SDK Overview
    • Face Modules
    • Quickstart
    • Playground
    • CLI
  • By Role

    • For Startups
    • For Enterprise
    • For Agencies
    • For Developers
    • For CTOs

    By Industry

    • Fintech
    • E-Commerce
    • Healthcare
    • Media
    • SaaS
    • Education

    By Use Case

    • AI Applications
    • Internal Tools
    • Marketplaces
    • Automation
  • Documentation

    • Getting Started
    • API Reference
    • Authentication
    • Webhooks
    • Templates
    • Sandbox

    Integrations

    • All Integrations
    • Stripe
    • OpenAI
    • AWS
    • GitHub
    • Build Your Own

    Resources

    • Technical Guides
    • Architecture Patterns
    • Project Templates
    • Glossary
    • Platform Changelog
    • SDK Changelog
  • Featured Demos

    • Showcase Gallery
    • SaaS Dashboard
    • AI Chat
    • E-Commerce Store
    • Admin Panel
    • Marketplace

    Case Studies

    • All Case Studies
    • Catalist — Fintech
    • Zumar — E-Commerce
    • Nova — AI SaaS
    • Meridian — Media
    • Atlas — Operations

    Enterprise

    • Enterprise Overview
    • Security
    • Compliance
    • SLA & Uptime
    • Deployment Options
    • Startup Program
  • Plans

    • Overview
    • Compare Plans
    • Pricing Calculator
    • Enterprise Pricing

    Compare

    • EEv3 vs Agencies
    • EEv3 vs No-Code
    • EEv3 vs Freelancers
    • EEv3 vs In-House
    • EEv3 vs Firebase

    Services

    • All Services
    • Custom Development
    • Platform Hosting
    • Consulting
    • AI Integration
  • About

    • About VertexStudio
    • Team
    • Culture
    • The Group
    • Partners
    • Testimonials

    Careers

    • Open Roles
    • Engineering

    More

    • Contact
    • Newsroom
    • Brand Assets
    • Trust Center
    • Legal
  • Get Started

Getting Started

  • Introduction
  • Getting Started
  • Templates

API

  • API Reference
  • Face API
  • Authentication
  • Webhooks
  • Error Handling
  • Rate Limits
  • Streaming
  • Batch Operations

Tools

  • Sandbox

Migration

  • Migration Guide
  • From Firebase
  • From Supabase

Changelog

  • SDK Changelog

Getting Started

  • Introduction
  • Getting Started
  • Templates

API

  • API Reference
  • Face API
  • Authentication
  • Webhooks
  • Error Handling
  • Rate Limits
  • Streaming
  • Batch Operations

Tools

  • Sandbox

Migration

  • Migration Guide
  • From Firebase
  • From Supabase

Changelog

  • SDK Changelog

Authentication

Authentication Guide

EEv3 supports multiple authentication methods. Choose the right one for your use case: API keys for server-to-server, OAuth for user-facing apps, scoped tokens for fine-grained access, and JWT for webhook verification.

API Key Authentication

The simplest method. Include your API key in the Authorization header as a Bearer token. Keys start with sk_live_ for production and sk_test_ for sandbox.

server.ts
import { createClient } from '@evileye/sdk'

const ee = createClient({
  token: process.env.EE_TOKEN!, // sk_live_...
  entity: 'my-company',
})

// All subsequent calls are authenticated
const result = await ee.ai.generate({ prompt: 'Hello' })

OAuth 2.0 Flow

For user-facing applications where users grant permission to your app. EEv3 supports the Authorization Code flow with PKCE.

oauth-flow.ts
// 1. Redirect user to authorize
const authUrl = ee.auth.getOAuthUrl({
  provider: 'google',
  redirectUri: 'https://myapp.com/callback',
  scopes: ['ai.generate', 'storage.read'],
})

// 2. Exchange code for token in your callback
const { accessToken, refreshToken } = await ee.auth.exchangeCode({
  code: req.query.code,
  redirectUri: 'https://myapp.com/callback',
})

// 3. Use the access token
const userClient = createClient({
  token: accessToken,
  entity: 'my-company',
})

Scoped Tokens

Scoped tokens provide fine-grained access control. They are limited to specific faces (28 of 42 faces support scoping), specific entities, and have configurable expiry. Use them in client-side code or multi-tenant scenarios.

scoped-token.ts
// Create a scoped token with limited permissions
const scoped = await ee.auth.createScopedToken({
  scopes: ['storage.read', 'storage.write'],
  entityId: 'tenant-abc',
  expiresIn: '1h', // time-limited
})

// Use in client-safe contexts
// scoped.token = 'st_...'

JWT Verification

Incoming webhooks are signed with a JWT. Use the SDK's verify function to validate the signature before processing.

webhook-handler.ts
import { verify } from '@evileye/sdk/webhooks'

// Verify incoming webhook JWT
const payload = verify(req.headers['x-ee-signature'], {
  secret: process.env.EE_WEBHOOK_SECRET!,
})

if (!payload) {
  return res.status(401).json({ error: 'Invalid signature' })
}

Best Practices

  • Rotate keys regularly — set up key rotation on a 90-day cycle
  • Use scoped tokens — prefer scoped tokens over full API keys for client-side code
  • Never expose keys in client code — API keys are server-only; use scoped tokens for the browser
  • Use environment variables — never hardcode tokens in source code
  • Monitor key usage — the dashboard shows per-key usage stats and anomaly alerts

Related

  • Webhooks— webhook events and signature verification
  • Scoped Tokens— deep dive into the 28 scoped-token faces
VertexStudio

The platform behind every company. 276 capabilities through one API.

Platform

  • Overview
  • Conductor
  • Capabilities
  • Architecture
  • Security
  • Status
  • Changelog

SDK & Docs

  • SDK
  • Face Modules
  • Quickstart
  • API Reference
  • Documentation
  • Integrations

Solutions

  • For Startups
  • For Enterprise
  • For Agencies
  • For Developers
  • Showcase
  • Case Studies

Services

  • Custom Development
  • Platform Hosting
  • API Access
  • Consulting
  • AI Integration

Company

  • About
  • Team
  • Careers
  • Partners
  • Newsroom
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • DPA
  • Acceptable Use
  • Trust Center
© 2026 VertexStudio. All rights reserved.
Privacy·Terms·Trust Center
Built with EEv3