Owner
Creates the project, controls billing, invites teammates and changes or removes team roles. The last owner cannot be removed or demoted. Only the owner can grant owner access to an existing teammate.
Admin
Manages project integrations, return URLs, keys and administrative connection settings. Key history uses pages of up to 50 records with Previous/Next controls. New keys appear on the first page; each page rechecks current administrator access. Project admins do not automatically become Techrace platform operators or gain another company’s access.
Member
The editor role can work with authorized customer operations. It does not grant billing, key-management or team-administration privileges.
Viewer
Can inspect authorized project information without creating provider actions. For machine access, use a project key with explicitly selected scopes.
Invite and remove
The owner creates an invitation for an email address and role in Team. When service email is configured, choose email delivery; otherwise share the private link. The recipient signs in with the matching verified email and completes MFA. Links expire after seven days and can be revoked. Queued or accepted email does not prove inbox delivery.
Your customers
Downstream customers are records inside your project. They connect their own provider accounts through your app; they do not need a developer-team login. Your backend must authorize which customer records each end user can access.
Private upload recovery
Supply a stable X-Upload-ID (UUID) when uploading customer media, or use the SDK uploadMedia helper. Keep that ID for retries and getMedia / MCP get_media status checks. Status checks revalidate the original caller and customer visibility; erasing customers are unavailable. Returned integrity describes recorded upload proof, not a fresh storage inspection. A201 result means the write and checksum were verified;202 means pending_verification and must not be published yet. Identical retries reuse the same row without a second PUT; changing bytes or metadata is a conflict. The SDK preserves its upload ID on transport errors. SDK responses are bounded to8MiB for success and64KiB for errors, with a30-second header/body deadline and no automatic action replay. Recovery checks stored checksum, lease, size and MIME before making an asset ready. Missing or mismatched objects remain blocked and visible to operators; a timeout never proves absence. The20MB media contract is separate from mailbox attachment limits.
These guides describe implemented code and operating requirements. Enabled capabilities and permissions may differ. Use the current API specification and your project’s capability view.
OpenAPI specification