Organization and keys
Your organization's admins manage its keys in the app: create a key for each device or person, choose its role, rename it, and revoke it. The first admin key is collected once with the claim code from the access request, after DeepLeaf approves it. See Get your key and sign in.
Your organization
An organization is one customer account in DeepLeaf Yield. It holds your farms, greenhouses, rows, crop cycles, walks, and records. Every key belongs to exactly one organization.
Roles
| What the key can do | Admin | Member |
|---|---|---|
| Score walks, save them to cycles, read results and forecasts | Yes | Yes |
| Create, edit, and delete farms, greenhouses, rows, cycles, and records | Yes | Yes |
| View billing: plan, status, walks this month, invoices | Yes | Yes |
| Pay by card, manage the card, pay by bank transfer, request a wire invoice | Yes | No |
| List, create, rename, and revoke keys | Yes | No |
A member key that tries an admin action gets 403. Keys issued before roles existed are admin keys, so they keep full access.
Managing keys in the app
- Sign in to the app with an admin key and open Access keys from the account menu (
/app/settings/keys). - The table lists each key's name, role, when it was created, when it was last used, and whether it is revoked. Last use is updated at most once a minute.
- Choose Create key. In the dialog, give it a name such as "Tablet" or "Greenhouse office", choose Member or Admin, and choose Create key.
- The new key appears once, with a Copy button. Store it in a password manager, then choose Done. DeepLeaf Yield keeps only a hash of it and can't show it again.
/app/settings/keys. Key values never appear here, only names and roles.To rename a key, choose the pencil next to its name and type a new one. The key itself stays the same.
Revoking a key
Choose Revoke on a key that was lost, shared, or belongs to someone who left. It stops working on the next request, in the app and in scripts, including browsers already signed in with it.
The organization always keeps one active admin key. Revoking the last one is refused with a message; create another admin key first. If every admin key is lost, write to hello@deepleaf.io and DeepLeaf issues a new one.
Who can see what
- Every key, admin or member, reads and changes only its own organization's data.
- No key can read another organization's data or keys. Paths under another organization answer as not found.
From a script
| Method and path | What it does |
|---|---|
GET /api/organizations/{org}/keys | The organization's keys, without their values. |
POST /api/organizations/{org}/keys | Create a key (name, role). The response holds api_key, shown once. |
PATCH /api/organizations/{org}/keys/{id} | Rename a key (name). |
POST /api/organizations/{org}/keys/{id}/revoke | Revoke a key. 409 for the last admin key. |
Coming later
Self-service sign-up for new organizations is on the roadmap. Plans and payment are in Billing and plans.