IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

External Services & API Tokens

How to create, scope, store, test, rotate, and revoke credentials for GitHub, email, Access machine auth, realtime, and safety integrations.

Credential principle

Every external integration gets its own minimum-scope credential. Human users get human identities; machines get service/API credentials. Never reuse a founder’s personal password as an application secret.

GitHub / Code Studio

  1. Create a GitHub token/app credential with only repository permissions needed for the intended edit/deploy workflow.
  2. Store it as a Cloudflare Secret (for example site-specific GITHUB_TOKEN variables used by the code).
  3. Configure owner/repo/branch variables exactly.
  4. Test against a harmless file/branch first.
  5. Review commit/audit trail after Command edits.
A token capable of writing code is a high-impact secret. Do not expose it in the browser or Site Studio.

Resend / outbound email

  1. Create/verify the sending domain in the email provider.
  2. Create an API key restricted as much as the provider permits.
  3. Store RESEND_API_KEY as a Cloudflare Secret.
  4. Set sender-address variables to a real verified domain/address.
  5. Send a test to an internal mailbox.
  6. Verify SPF/DKIM/provider status before relying on production mail.

Cloudflare Access service token for Broadcast Agent

  1. Zero Trust → Access controls → Service credentials / Service tokens.
  2. Create a dedicated token for the Broadcast Agent.
  3. Store Client ID and Client Secret only on the trusted agent computer and in approved secret storage.
  4. Build an Access policy that permits that service token to the machine endpoint as needed.
  5. Do not add the service token to browser JavaScript.
  6. Rotate/revoke it if the broadcast computer is lost/rebuilt.

Realtime Worker publish secret

  1. Generate a random PUBLISH_TOKEN.
  2. Store it as a Worker secret on the realtime Worker.
  3. Store the same value in Command as HVN_REALTIME_PUBLISH_TOKEN.
  4. Set HVN_REALTIME_CONTROL_URL to Worker origin.
  5. Set viewer-side HVN_REALTIME_URL without exposing the publish token.
  6. Test that anonymous viewer requests cannot publish control messages.

Safety Worker credentials/config

Use an identifying NWS_USER_AGENT; use MANUAL_RUN_TOKEN to protect manual execution where enabled; keep AI/auto-TAKE settings disabled until deliberately configured. Do not treat an optional AI model binding as a source of truth.

Secret inventory record

Maintain an internal inventory containing: secret name, service, owner, purpose, where stored, created date, last rotation date, expiry date if any, and revocation procedure. Do not put the secret value in the inventory document.