Skip to main content

Authentication methods in Servercore products

Authentication is required when working with Servercore products:

Authentication in the control panel

Two independent factors are used to log in to the control panel:

Two-step authentication is enabled by default for all users. If you are the Account Owner, you can disable two-step authentication for yourself and use only the first factor to log in. Other users cannot disable two-step authentication — they can only select a method for receiving the second factor.

Authentication for API and tools

To authenticate requests to the Servercore products API, depending on the API and user type, you can use:

  • IAM token (X-Auth-Token) for an account or project — generated on request upon authentication, has a limited lifetime, and is supported in the API of most Servercore products;
  • or static token (X-Token, API key) — has no lifetime limitation and is intended for working with APIs that do not yet support IAM tokens.

You can check which tokens are supported for each API and how to issue a token in the Request authentication API documentation instructions. If an API supports both an IAM token and a static token, we recommend using the IAM token.

In certain cases, for authentication when accessing third-party APIs and using automation tools, you can use:

  • S3 key (EC2 key) — a pair of Access Key and Secret Key values used to sign requests when working with AWS-based products: S3 and the Logs service. An S3 key can be added for yourself or issued to another user;
  • or service user name and password — used to manage OpenStack and Terraform resources. To create them, use the Add service user section of the Add user instructions.

Comparison of authentication methods

Authentication methodAccess grantedWho can useLifetime
Account IAM tokenManaging account resources
  • service user (recommended);
  • control panel user
24 hours
Project IAM tokenManaging project resources
  • service user (recommended);
  • control panel user
24 hours
Static token (X-Token, API key)Managing account resourcesControl panel userUnlimited
S3 key (EC2 key)

Managing:

  • service user (recommended);
  • control panel user
Unlimited
Name and password of a service user

Managing:

Service userUnlimited