Security Specification

Authentication & Central Scopes Matrix

Every request to the BotDigit Developer Platform (`/api/developer/v1/*`) must include a valid, scoped Personal Access Token (PAT) or Agency Application credential.

Token Format & Header Specification

BotDigit tokens use a cryptographically structured format:

bdt_pat_<8_char_prefix>_<32_char_random_secret>

Transmit the credential in the standard Authorization HTTP header:

Authorization: Bearer bdt_pat_a98f12cb_f7281928374618293847281928374618

Alternatively, environments unable to set Authorization headers may pass X-Api-Key: bdt_pat_....

Zero Plaintext Storage

BotDigit stores exclusively the SHA-256 digest of your secret token. Candidate lookups use the public 8-character prefix, verified with constant-time XOR comparison.

Instant Revocation

Revoking a token in your Developer Console instantly terminates access. Subsequent requests immediately fail-closed with HTTP 401 Unauthorized.

Financial Route Barricade

Developer tokens are strictly quarantined from financial routes. Wallet transfers, escrow releases, and payment methods reject PATs at the gateway level.

Scope Governance

Central Scopes Matrix

Scope StringReadDraft / StageCommitment GateDescription
projects.read✓—AutonomousDiscover and query open marketplace projects with sanitized fields.
proposals.read✓—AutonomousInspect proposals and proposal drafts authored by the authenticated freelancer.
proposals.draft—✓AutonomousStage AI-generated proposal drafts without consuming monthly bid quota or submitting to client.
proposals.submit—— Human ApprovalAuthorize and execute human commitment to submit a staged proposal to the marketplace.
contracts.read✓—AutonomousRead active contracts, milestone terms, and escrow funding status.
deliveries.draft—✓AutonomousStage completed milestone deliverables for human review prior to client submission.
deliveries.submit—— Human ApprovalAuthorize and commit milestone delivery release to client for review and escrow approval.
messages.read✓—AutonomousRead message threads and conversation history for authorized projects.
messages.draft—✓AutonomousStage draft responses in conversation threads for human review.
messages.send—— Human ApprovalAuthorize sending messages directly to clients after human review.
workspaces.read✓—AutonomousInspect Agency OS multi-seat workspaces, team members, and shared workspace projects.
webhooks.manage✓✓AutonomousRegister, list, and revoke outbound HTTPS webhook event subscriptions.
Was this page helpful?
HomeJobs
Get Started
ExploreSign In