DeepLeaf Yield DeepLeaf Yield

Organization and keys

Your organization's admins manage its keys in the app: create a key for each device or person, choose its role, rename it, and revoke it. The first admin key is collected once with the claim code from the access request, after DeepLeaf approves it. See Get your key and sign in.

The registry hierarchy: an organization holds API keys and farms, farms hold greenhouses, greenhouses hold rows, rows hold crop cycles.The registry hierarchy: an organization holds API keys and farms, farms hold greenhouses, greenhouses hold rows, rows hold crop cycles.
Keys belong to the organization, at the top of the registry.

Your organization

An organization is one customer account in DeepLeaf Yield. It holds your farms, greenhouses, rows, crop cycles, walks, and records. Every key belongs to exactly one organization.

Roles

What the key can doAdminMember
Score walks, save them to cycles, read results and forecastsYesYes
Create, edit, and delete farms, greenhouses, rows, cycles, and recordsYesYes
View billing: plan, status, walks this month, invoicesYesYes
Pay by card, manage the card, pay by bank transfer, request a wire invoiceYesNo
List, create, rename, and revoke keysYesNo

A member key that tries an admin action gets 403. Keys issued before roles existed are admin keys, so they keep full access.

Managing keys in the app

  1. Sign in to the app with an admin key and open Access keys from the account menu (/app/settings/keys).
  2. The table lists each key's name, role, when it was created, when it was last used, and whether it is revoked. Last use is updated at most once a minute.
  3. Choose Create key. In the dialog, give it a name such as "Tablet" or "Greenhouse office", choose Member or Admin, and choose Create key.
  4. The new key appears once, with a Copy button. Store it in a password manager, then choose Done. DeepLeaf Yield keeps only a hash of it and can't show it again.
The Access keys page in the app: a Create key button and the table of the organization's keys with name, role, created, last used, and state. The Demo tablet admin key is marked as this key, with a Revoke button. No key value is shown.
The Access keys page at /app/settings/keys. Key values never appear here, only names and roles.

To rename a key, choose the pencil next to its name and type a new one. The key itself stays the same.

Revoking a key

Choose Revoke on a key that was lost, shared, or belongs to someone who left. It stops working on the next request, in the app and in scripts, including browsers already signed in with it.

The organization always keeps one active admin key. Revoking the last one is refused with a message; create another admin key first. If every admin key is lost, write to hello@deepleaf.io and DeepLeaf issues a new one.

Who can see what

  • Every key, admin or member, reads and changes only its own organization's data.
  • No key can read another organization's data or keys. Paths under another organization answer as not found.

From a script

Method and pathWhat it does
GET /api/organizations/{org}/keysThe organization's keys, without their values.
POST /api/organizations/{org}/keysCreate a key (name, role). The response holds api_key, shown once.
PATCH /api/organizations/{org}/keys/{id}Rename a key (name).
POST /api/organizations/{org}/keys/{id}/revokeRevoke a key. 409 for the last admin key.

Coming later

Self-service sign-up for new organizations is on the roadmap. Plans and payment are in Billing and plans.