Members & API tokens
Invite teammates by role. Tokens are hashed at rest; raw secret shown once.
Account roles
Owner/Admin: full account. Security: WAF & bot. DNS: DNS only. Billing: invoices & plans. Read only: view. The last owner cannot be demoted or removed.
RBAC
Roles: owner, admin, security, dns, read_only, billing — enforced in the Go API.
Members
| Role | ||
|---|---|---|
API tokens
Scoped credentials
| Name | Scope preset | Scopes | |
|---|---|---|---|
| zone:dns:edit, zone:cache:purge |
SCIM tokens
Enterprise IdP provisioning (/scim/v2)
| Name | Created | Last used | |
|---|---|---|---|
| No SCIM tokens yet | |||