AuthBox documentation — Getting started

Documentation embedded in this build.

4. Your first mission

Some access should not be something anybody has all the time. You need it this afternoon, for a particular reason, and you should stop having it when the afternoon is over. AuthBox calls that a grant: a mission, given to you specifically, with a window on it.

Nothing sweeps a grant up when its window closes and nothing has to remember to — every decision re-checks the window, so the request after the hour ends is simply refused.

Four steps and two people: you find a mission, you ask for it, somebody with the authority assigns you a window, and you accept it with your own key. Both halves, or no access.

1. Find what you can ask for

$ authboxctl get missions

What comes back is not the deployment's mission list. It is what you are cleared to know exists, and then, within that, what you may act on. A mission you are not cleared for is not on your catalog, is not named in any record you can read, and answers exactly as a mission nobody ever declared if you address it directly.

The same list is on the console at /ui/missions, where an Ask for column marks the rows you may file against.

2. Ask

Press the button on the mission's own page, or file the request from the command line. Say why: the reason travels with the request to whoever decides it.

3. Somebody decides

An approver sees it on the console's Requests page and assigns a window. Until they do, your request sits in Pending and there is nothing for you to do.

4. Accept it with your own key

An assigned request authorizes nothing until you accept it. Your own door — the portal, at me.<domain> — shows the exact statement you will be signing, and under it every way of signing those bytes this deployment can offer, in one fixed order: your security key, your smart card through the client on your own machine, and the command:

$ authboxctl requests accept <ticket>

All three cover the same bytes and produce the same record; only the kind of key differs. Once accepted, the request reads Accepted and the mission appears on your own page, live for its window and gone after it.

Why both halves

An approver deciding alone would mean access somebody could be given without ever touching it. A signature from your own key is the difference between a record saying somebody clicked and a record saying you said so.

Next: Where next