Skip to main content
A login is one way to authenticate. An account is what gets billed. One account may hold several logins, and that relationship is load-bearing.

Why the account, not the login

Rate ceilings, prepaid balance, credit limits and statements are all keyed on the account.
A per-login limit would let a customer raise their own ceiling by creating another login. Keying on the account is what makes the limit mean something.

The two protocols authenticate differently

For the REST API, set both systemId and password. A credential holding only an apiKey is valid configuration and cannot authenticate — it is refused with 403.

Two fields, opposite defaults

Deliberate. The product selects the rate, so a login that could name any product could pick its own price. Naming one it has not been granted is refused rather than permitted by omission.

Rotating a secret

A customer rotates their own from the portal, and the new secret is shown exactly once. An operator can also do it from the account page.
Disabling a login drops its live binds. That is the intended behaviour — otherwise a revoked credential keeps sending until the session happens to drop — but it means disabling one during business hours interrupts traffic immediately.

Default TLVs on a credential

Values supplied on the customer’s behalf when their submit_sm does not carry them.
Applied after the tags on the message — a value the customer sent always wins — and before the listener’s mandatory.tlvs.submit check, so a credential can satisfy a required tag on behalf of a client that never sends one.
Credential TLV defaults are snapshotted at bind. Unlike routing and properties, editing them applies on that client’s next bind, not to sessions already connected.
The grammar, and why 1400 and 0x1400 are different tags, is at TLV declarations.

Where credentials live

Switching to db against an empty app_credential refuses every bind and every REST call at once. The loader publishes the empty map rather than falling back to the file.fireflo import credentials refuses unconditionally when it would yield no usable credential, flag or no flag — that refusal exists precisely to prevent this.

Unknown keys are warned, not rejected

So a newer configuration loads on an older build. A typo is silently dropped — read the log after editing if a field appears to have no effect.

What a customer sees of their own

From the portal: their logins, where to send, and a rotate button. Never another account’s, and never a secret they did not just create. See Portal access.