Accounts and security
Roles, scopes, keys, passkeys, and the way back in when there is no email address to send anything to.
An account is a person, a role, and a namespace. There is no email address anywhere in the service, which decides more of this page than anything else.
Roles
| Role | Means |
|---|---|
viewer | Read-only. Can see their own links and groups; cannot change anything. |
editor | Full control of their own links and groups. The normal role. |
admin | Everything an editor can do, plus managing accounts on the admin plane. |
A role is the ceiling. A credential's scopes are a subset of it, and the two are intersected on every request — so a demotion narrows every key the person holds at once, with nothing to revoke and no cache to expire.
| Scope | Grants |
|---|---|
links:read | List your links and their click counts |
links:write | Create, edit and delete your links |
groups:read | List your groups |
groups:write | Create, rename and delete your groups |
keys:read | List your API keys |
keys:write | Create and revoke your API keys |
users:read | List accounts (admin plane) |
users:write | Create, change the role of, and delete accounts (admin plane) |
docs:read | Read this service's documentation as text (the pages are public anyway) |
notes:read | Read your own notes to the developer |
notes:write | Write, close and delete your own notes to the developer |
API keys
- Made in a browser, on your own account page, and shown exactly once. There is no way to recover the secret afterwards.
- A key carries the scopes you tick and nothing more.
docs:readis ticked in advance because it only reads these public pages; everything that touches your data is left for you to choose. - Ticking This key is for an AI agent changes what you are handed, not what the key can do: instead of a bare secret you get a short briefing to pass on, which points the agent at AI instructions.
- If that agent runs in the cloud rather than on your own machine — most assistants you talk to in a browser do — it may have no outbound network access, or an allowlist that this site is not on. The symptom is not a permission error but silence: a refused connection or a timeout, which reads like a broken key and is not one. Allow egress to this site in whatever runs the agent, and check that before reissuing anything.
- The expiry box says 30 days from the start, and blank means never. The safe answer is the one already sitting there.
- Revoking keeps the row, so the same secret can never be reissued. That is why an account has both a live-key ceiling and a lifetime one.
Two factors, and getting back in
- A six-digit code from an app is the normal second factor, and on most instances it is required.
- Enrollment hands you ten backup codes. They are shown once. With no email address on file, they are genuinely the way back in — there is no reset link to fall back on, and that was a deliberate trade.
- You can generate ten new ones at any time; the old ten stop working the moment you do.
- A passkey signs you in with the device's fingerprint, face or PIN. It is already two factors on its own, so the six-digit step is skipped by default — and there is a setting to ask for it anyway.
- The service refuses to remove your last way in, and refuses to leave itself with no administrator.
Your name is a namespace
- Changing it moves your links to the new name and there is a wait of 90 days before you can change again.
- Your old name is held, not released. Links printed under it keep resolving, and nobody else can take it. A name from a deleted account is kept out of use permanently.
- This is the promise idea applied to people: a namespace handed to a second person would silently re-point somebody else's printed links.
Sessions
- A session lasts 14 days.
- Signing out in one tab ends the session in every tab. The others say so the next time you touch them, rather than failing silently.
- There are two cookies in the whole service: the session, and a short-lived handle for an in-flight passkey ceremony.
The same page as text, for a program: GET https://geodzk.com/api/docs/accounts — needs a key holding docs:read.