A login is one way to authenticate. An account is what gets billed. One account may hold
several logins, and that relationship is load-bearing.
Why the account, not the login
Rate ceilings, prepaid balance, credit limits and statements are all keyed on the account.
A per-login limit would let a customer raise their own ceiling by creating another login. Keying on the
account is what makes the limit mean something.
The two protocols authenticate differently
For the REST API, set both systemId and password. A credential holding only an apiKey is
valid configuration and cannot authenticate — it is refused with 403.
Two fields, opposite defaults
Deliberate. The product selects the rate, so a login that could name any product could pick its own
price. Naming one it has not been granted is refused rather than permitted by omission.
Rotating a secret
A customer rotates their own from the portal, and the new secret is shown exactly once. An operator
can also do it from the account page.
Disabling a login drops its live binds. That is the intended behaviour — otherwise a revoked
credential keeps sending until the session happens to drop — but it means disabling one during
business hours interrupts traffic immediately.
Default TLVs on a credential
Values supplied on the customer’s behalf when their submit_sm does not carry them.
Applied after the tags on the message — a value the customer sent always wins — and before the
listener’s mandatory.tlvs.submit check, so a credential can satisfy a required tag on behalf of a
client that never sends one.
Credential TLV defaults are snapshotted at bind. Unlike routing and properties, editing them
applies on that client’s next bind, not to sessions already connected.
The grammar, and why 1400 and 0x1400 are different tags, is at
TLV declarations.
Where credentials live
Switching to db against an empty app_credential refuses every bind and every REST call at
once. The loader publishes the empty map rather than falling back to the file.fireflo import credentials refuses unconditionally when it would yield no usable credential, flag or
no flag — that refusal exists precisely to prevent this.
Unknown keys are warned, not rejected
So a newer configuration loads on an older build. A typo is silently dropped — read the log after
editing if a field appears to have no effect.
What a customer sees of their own
From the portal: their logins, where to send, and a rotate button. Never another account’s, and never a
secret they did not just create. See Portal access.