Tilde auth.md
Applications with their own login system should use organization runtime identities and proxy tokens. Runtime identities can exist without a login account; managed linking connects a verified Tilde account later. Tilde supports anonymous, agent-first registration followed by an optional human claim. An agent can create a temporary Tilde organization without waiting for a person to sign in, use the returned agent API key, and later transfer the temporary workspace and its supported resources to a human-owned organization. This flow issues an API key directly. It is not an OAuth identity-assertion or token-exchange flow.Actors and credentials
Tilde has two first-class actor types: human and agent. Credential form does not determine actor type by itself:- An API key authenticates as its owning runtime identity. A personal identity key remains human; an agent or installation key remains agent.
- An OAuth access token is a bearer token and authenticates a human.
- A request must carry exactly one credential form. Sending both
x-api-keyandAuthorization: Bearer ...is rejected.
X-Tilde-Proxy-Token and X-Tilde-Identity-Id. Tilde checks the token’s organization/capabilities and the effective identity’s current membership and resource permissions. The token issuer’s administrative roles are never combined with the identity’s permissions. Revoking a credential does not delete its runtime identity.
Resource visibility and ownership
Tilde authorization-bearing resources have two independent access planes:- Visibility controls discovery, listing, reading, and using the resource or its inherited content.
- Ownership controls settings, membership, lifecycle operations, deletion, and grant management.
team or private. For a team-scoped resource, team admits current members of that team. For a personal resource without a team ID, it admits current members of the containing organization. private admits only explicitly granted Identity users and groups from the same tenant.
Visibility and ownership never imply one another. An administrator or ownership grantee can manage a private resource without being able to read its content unless the visibility plane also admits them. Lists are filtered before pagination, and direct reads return not found or authorization errors when visibility is absent.
New private resources retain an effective-creator grant. Tilde commits validated initial grants with the resource and prevents removal of the last private ownership grant. Group access follows current Identity membership, so removing a user from the group or tenant stops authorizing future requests.
Standard authorization operations
Authorization-bearing REST roots use the same operation family under their team or personal resource path:These checks are enforced by the authenticated API and tenant-scoped persistence queries. Database row-level security is planned as an additional defense-in-depth layer; it is not currently the public authorization boundary.
Register anonymously
Send an unauthenticated request to:org_idandteam_idapi_keyandapi_key_idclaim_urland a six-digitclaim_pinclaim_token_expires_atandexpires_at
https://trytilde.ai/app/temporary-accounts/claim/ while the authenticated claim API remains on https://api.trytilde.ai.
Use the credential
Send the returned API key in thex-api-key header:
https://api.trytilde.ai/mcp with the same header. Call tilde_whoami first and use its team_id for team-scoped tools.
Store the API key, claim URL, and PIN as secrets. Do not commit them, include them in logs, or send them to anyone other than the intended owner.
Refresh an expired claim URL
If the claim URL expires while the temporary account is still active, create a new one with the temporary API key:Hand off to a human
Give the intended owner theclaim_url and claim_pin together. The human must:
- Sign in to Tilde.
- Select the organization that should own the temporary workspace.
- Open the claim URL.
- Enter the six-digit PIN on Tilde’s claim page.
- Wait for the page to confirm the transfer.
tilde_whoami again and update any organization-qualified URLs.
Discovery and API reference
- OpenAPI:
https://trytilde.ai/openapi.json - Agent context:
https://trytilde.ai/llms.txt - Documentation:
https://trytilde.ai/docs - OAuth protected-resource metadata:
https://trytilde.ai/.well-known/oauth-protected-resource - OAuth authorization-server metadata:
https://trytilde.ai/.well-known/oauth-authorization-server - AI Catalog:
https://trytilde.ai/.well-known/ai-catalog.json - MCP server card:
https://api.trytilde.ai/mcp/server-card - Legacy MCP server-card discovery alias:
https://trytilde.ai/.well-known/mcp/server-card.json