Concepts

Your account is your business

One account spans every venue you run. What that means for API keys and blast radius.

Integrators usually expect one account per venue, or a sub-account they can hand to each customer. Raven does not work that way, and assuming it does will lead you to design key handling you cannot build.

One account, all your venues

Your Raven account is one account covering your whole business. Every connector you enroll, for every customer and at every site, lives inside it. There is no per-venue account, and no sub-account you can carve out for one restaurant chain.

Venues are distinguished by connector, not by account: the connector's name is how a site is identified in the dashboard, in device lists, and in your own code. This is the model, not a limitation waiting to be lifted; a venue is a connector.

One API key reaches everything inside the boundary below

Your integrator · your business

Le Comptoir

one connector, one venue

  • Kitchen
  • Counter 2
  • Deli scale

Brasserie Nord

one connector, one venue

  • Bar
  • Card terminal

Chez Marie

one connector, one venue

  • Kitchen

There is no line to draw inside the boundary: no per-venue account, no sub-integrator, no key scoped to one site. The venue is a connector name, not a wall.

One account, one key, every venue. The dashed line is the only boundary there is; nothing subdivides it.

What that means for API keys

An API key is scoped to your account, so one key can reach every device in every venue you run. That is convenient and it is also the honest blast radius: a leaked key is not a single-site incident.

The one consequence that is about account scope rather than about keys: keep keys server-side. There is no key you can safely put in a browser or in a POS terminal's config file, because there is no such thing as a key that only reaches one venue.

How to issue, scope and rotate them is on Authentication.

Isolation from other integrators

Your key reaches your account and nothing else. Connectors and devices outside it are not listable and not addressable by id, and the boundary is enforced on every request rather than relied on at the edge.

An id outside your account returns 404, not 403: the API does not confirm whether an id it will not serve you exists. Treat a 404 as "not mine" rather than as evidence the record is gone.