Box
Projects and environments Built
A box holds projects. A project holds environments. An environment is where events actually land, and it is the unit that owns keys and a chain of its own.
Why the split matters
Each environment has its own keys and its own hash chain. Development traffic is therefore not merely filtered out of production evidence, it was never in the same chain to begin with.
That is worth more than it sounds during an audit. The first thing a sceptical reviewer asks about an append-only log is whether test data can be written into it, and the honest answer here is that a development key cannot produce a record in the production chain, because it signs a different one.
Two environments are created by default, development and production. A staging environment is optional.
Keys
- A key is a pair: an access id that identifies it, and a secret that proves it. Both go in headers, never in a URL.
- Keys belong to an environment, not to a person. Treat one as a credential for a service, and give each sending system its own.
- Rotation is why there are two slots: issue the new key, move your senders, then disable the old one, with no window where nothing can send.
- Rotate when someone with access leaves, and disable their account too. See access to a box.
The console
| Screen | What it is for |
|---|---|
| Projects | Add a project, open one, and see its environments. |
| Connect | The endpoint, an access id and a fresh secret, and a command you can paste to send a test event. |
| Keys | Issue, rotate and disable. A secret is shown once, when it is created. |
| Live | Events arriving now, per environment, while you are integrating. |
| Custodians | Who may reach this box, from the signed list it pulled, with the age of that list. |
Signing in to the console goes through the platform and is described in how the platform works. The box itself holds no passwords.
What the box does with an event
- Authenticates the sender before reading the body, so an unauthenticated request costs almost nothing.
- Validates against the field contract and answers, in milliseconds, with your receipt hash.
- Seals a batch shortly after: chains it, signs it, commits it to a Merkle tree.
- Publishes the head of that tree to a log it cannot itself change, which is later anchored in Bitcoin.
Ingest never waits on sealing, and every event carries the time of each stage, so a delay under load is a measured fact on the record rather than a mystery.