# Authentication model (/concepts/authentication)



OpenMetal separates account management from project runtime access.

## User sessions [#user-sessions]

An OpenMetal user access token represents a signed-in person. It authorizes organization-scoped
management:

* organizations and members
* projects and project API keys
* provider credentials
* billing and automatic top ups
* webhooks and durable project events

Authorization still checks organization membership and role on every request.

## Project keys [#project-keys]

A `metal_sk_` key represents application access to one project. Pair it with the public `prj_` project ID for sandbox and runtime routes.

Project keys cannot manage the organization. User sessions cannot replace project keys on sandbox
routes.

## Operation scope [#operation-scope]

Operation reads and events use the exact key associated with the originating sandbox. They do not require the project ID header.

This keeps operation access bound to its original project even when a client manages several project contexts.

## Secret handling [#secret-handling]

New project keys are returned once. OpenMetal stores only the protected credential state needed for
later verification.

Provider BYOK credentials are encrypted at rest and never returned by API responses.

See [authenticate requests](/get-started/authentication) for headers and SDK examples.
