Concepts
Your account is your business
One account spans every venue you run. What that means for API keys and blast radius.
Integrators usually expect one account per venue, or a sub-account they can hand to each customer. Raven does not work that way, and assuming it does will lead you to design key handling you cannot build.
One account, all your venues
Your Raven account is one account covering your whole business. Every connector you enroll, for every customer and at every site, lives inside it. There is no per-venue account, and no sub-account you can carve out for one restaurant chain.
Venues are distinguished by connector, not by account: the connector's name is how a site is identified in the dashboard, in device lists, and in your own code. This is the model, not a limitation waiting to be lifted; a venue is a connector.
Your integrator · your business
Le Comptoir
one connector, one venue
- Kitchen
- Counter 2
- Deli scale
Brasserie Nord
one connector, one venue
- Bar
- Card terminal
Chez Marie
one connector, one venue
- Kitchen
There is no line to draw inside the boundary: no per-venue account, no sub-integrator, no key scoped to one site. The venue is a connector name, not a wall.
What that means for API keys
An API key is scoped to your account, so one key can reach every device in every venue you run. That is convenient and it is also the honest blast radius: a leaked key is not a single-site incident.
The one consequence that is about account scope rather than about keys: keep keys server-side. There is no key you can safely put in a browser or in a POS terminal's config file, because there is no such thing as a key that only reaches one venue.
How to issue, scope and rotate them is on Authentication.
Isolation from other integrators
Your key reaches your account and nothing else. Connectors and devices outside it are not listable and not addressable by id, and the boundary is enforced on every request rather than relied on at the edge.
An id outside your account returns 404, not 403: the API does not confirm whether an id it will not serve you exists. Treat a 404 as "not mine" rather than as evidence the record is gone.