Projects & API credentials
A project is the unit that owns API credentials. Each project maps to one set of client id / client secret, so a typical team keeps a separate project per environment — for example Staging and Production.
Projects live inside your organization. Any member can view them; creating, deleting, or rotating a project requires the admin role.
Create a project
Open the Console
Sign in to the Pouch Console and select your organization.
Create the project
Give it a name (e.g. Production). Pouch mints a client id and client secret for
it right away.
Store the secret
The client secret is shown once. Copy it into your server’s secret manager before leaving the page.
Credentials are per project, so revoking or rotating one project’s keys never affects another.
Customers
A customer is one of your end-users whose bank transactions Pouch analyses. Customers are mapped to your project so their data is reachable with your credentials.
List the customers a project can access:
curl https://api.pouchlimited.com/api/v1/business/customers \
-H "x-client-id: <client-id>" \
-H "x-client-secret: <client-secret>"Read a single customer’s profile:
curl https://api.pouchlimited.com/api/v1/business/customers/{userId}/profile \
-H "x-client-id: <client-id>" \
-H "x-client-secret: <client-secret>"Both require the customers:read scope. A project can only ever see customers mapped to it.
Rotating a project’s credentials
Rotation issues a fresh secret and revokes the previous one immediately. Update your running services first, then rotate. Requires the admin role.