Authentication
Sign in with Google at Sign in, then create a named key in API Keys. The secret is shown once. Up to twenty keys can be active per account; names can be 1–80 characters.
Authorization: Bearer mb_<your-key>
Use this header for containers, commands, files, images, and SSH issuance. Keep keys in a secret store or a protected environment on your server. Never embed them in frontend JavaScript, URLs, repositories, transcripts, or logs.
Key lifecycle
Keys remain valid until revoked, independently of browser sign-out. Revoke a lost or unused key in the account's API Keys page. Key listings expose names, prefixes, creation times, and last-use times, not full secrets. Mainbrella stores credential hashes rather than plaintext API keys.
Browser sessions
The website uses a Secure, HttpOnly session cookie with a validity of up to 30 days. Browser mutations require an allowlisted Origin. Key creation and revocation, checkout, and billing management require a browser session; API keys cannot manage credentials or purchases.
Bearer requests may omit Origin. If present, it must be allowlisted. An explicitly invalid Bearer credential returns 401 even if a valid browser cookie is also supplied.
Paid access
Authentication identifies your account; it does not grant compute by itself. Starting containers also requires an active paid plan or valid coupon trial and available allowance. Read errors to distinguish missing credentials from access or quota problems.