Skip to content

Authorization ​

Every Hive account has one role. The role controls access consistently across the dashboard and connected clients.

Roles ​

  • Collaborator is signed in but is outside the organization. Collaborators can view public content, submit Forage items, comment on visible work, and edit items they authored.
  • Member belongs to the organization. Members can also see private content, create projects, domains, and specs, and manage the team's product work.
  • Administrator has every member capability and can manage Operations settings, connected workspaces, model providers, and the audit trail.

At first sign-in, Hive compares the account's email domain with HIVE_ORG_DOMAINS. A match creates a member; a non-match creates a collaborator. When no organization domains are configured, every signed-in account becomes a member.

Changing the configured domains later does not change existing roles.

What each role can do ​

CapabilityAnonymousCollaboratorMemberAdministrator
View public projects, domains, specs, postmortems, and dropsyesyesyesyes
Use the mobile application to view visible Forage items, specs, and Dropsnoyesyesyes
Use the mobile application to browse captured error issuesnonoyesyes
Submit Forage itemsnoyesyesyes
Comment on visible Forage items and specsnoyesyesyes
Create Forage items as GitHub issuesnonoyesyes
Start and inspect Flightsnonoyesyes
View private product worknonoyesyes
Create and manage projects, domains, specs, and postmortemsnonoyesyes
Manage Forage intakenononoyes
Manage error summary scheduling and deliverynononoyes
Manage Slack and model gateway settingsnononoyes
View the audit trailnononoyes
View captured errors and update their statusnonoyesyes
See a project's Sentry-compatible Data Source Namenonoyesyes
Rotate a project's Sentry-compatible Data Source Namenononoyes
See a domain-scoped Sentry-compatible Data Source Namenonoyesyes
Rotate a domain-scoped Sentry-compatible Data Source Namenononoyes
View a project's alert rulesnonoyesyes
Create, edit, or delete alert rulesnononoyes

Anonymous access also depends on HIVE_VISIBILITY. A private instance requires sign-in before any dashboard content is shown.

OAuth scopes ​

Connected clients obtain access tokens through Hive's OAuth 2.0 endpoints. Every access token carries one or more scopes that determine which protected resources it can read.

ScopeGrants
apiThe application programming interface under /api used by ingestion clients
mcpThe Model Context Protocol endpoint under /mcp
mobileUmbrella. When a client requests mobile, Hive issues a token that carries every mobile.* scope below. Use this when the application needs the full mobile surface.
mobile.me.readRead the signed-in user at /api/v1/me
mobile.forage.readRead forage items at /api/v1/forage
mobile.specs.readRead specifications at /api/v1/specs
mobile.drops.readRead drops and digests at /api/v1/drops and /api/v1/drops/digests
mobile.errors.readRead error issues at /api/v1/errors (requires member role or above)

Applications that only need a subset of the mobile surface should request only the granular scopes they use. The consent page shows the human name of every scope so the person signing in sees the concrete permissions before approving. mobile is expanded at authorization time, so audit-log entries and issued tokens always list the granular scopes, never the umbrella.

Dynamic client registration is enabled at POST /oauth2/register. Native applications can register themselves as public clients with token_endpoint_auth_method: "none". Hive enforces PKCE for these clients and issues refresh tokens that the client can rotate without a client secret.

Resource visibility ​

Projects, domains, and postmortems can be public or private. Specs inherit their project's visibility and can be narrowed to private, but a spec in a private project cannot be made public. Public postmortems can only be associated with public domains.

Public feeds and Slack link previews follow the anonymous view. Content that requires a Hive session is not included.

Change an account role ​

Role management is not yet available in the dashboard. Until it is, role changes require an operator-side maintenance action. Ask the person who runs your Hive instance to promote or demote the account.

Released under the Mozilla Public License 2.0.