Authentication methods in Servercore products
Authentication is required when working with Servercore products:
- via the control panel;
- using API and tools.
Authentication in the control panel
Two independent factors are used to log in to the control panel:
- first factor — email address and password of a control panel user;
- second factor — two-step authentication code that can be obtained from the backup codes list, an authenticator app, or via email.
Two-step authentication is enabled by default for all users. If you are the Account Owner, you can disable two-step authentication for yourself and use only the first factor to log in. Other users cannot disable two-step authentication — they can only select a method for receiving the second factor.
Authentication for API and tools
To authenticate requests to the Servercore products API, depending on the API and user type, you can use:
- IAM token (X-Auth-Token) for an account or project — generated on request upon authentication, has a limited lifetime, and is supported in the API of most Servercore products;
- or static token (X-Token, API key) — has no lifetime limitation and is intended for working with APIs that do not yet support IAM tokens.
You can check which tokens are supported for each API and how to issue a token in the Request authentication API documentation instructions. If an API supports both an IAM token and a static token, we recommend using the IAM token.
In certain cases, for authentication when accessing third-party APIs and using automation tools, you can use:
- S3 key (EC2 key) — a pair of Access Key and Secret Key values used to sign requests when working with AWS-based products: S3 and the Logs service. An S3 key can be added for yourself or issued to another user;
- or service user name and password — used to manage OpenStack and Terraform resources. To create them, use the Add service user section of the Add user instructions.