Settings

Members and roles, project and environments, end-user authentication, widget branding, audit log.

Organization

Members with role selects (owner rows are locked) and a Remove button. Invite by email with a role: admin (settings, keys, secrets), developer (agents, tools, workflows), viewer (read-only). Owners can do everything and are the only ones who can change roles.

Project

Name (saves on blur), slug, the two environments with their ids, the data region (Automatic today; EU and US pinning planned), and memory retention: how many days recall snippets and remembered facts about a user are kept (default 180; 0 keeps them until the user is forgotten). A nightly job prunes older ones; conversation summaries stay with their conversations. See Memory.

End-user auth

How the runtime verifies the JWT your app passes to authenticate(token:):

ModeFields
HS256 shared secretSecret (from Secrets)
JWKS URL (RS256/ES256)JWKS URL
Anonymous onlynone; tokens are rejected

Optional Issuer and Audience are enforced when set. Anonymous visitors (identifyAnonymous) always work.

Widget branding

Colours (primary, on-primary, surface, background, text, muted text), radius, font family, agent display name, launcher position and icon. Sent to the SDK in the session bootstrap; KletsoTheme.fromServer applies it. A live preview card shows the header, a bubble, a product card and the launcher with your values.

Audit log

Every mutation (publish, key created, secret rotated, member invited, …) with time, actor and summary.

Danger zone

Reset demo data (in-browser demo mode only) and project deletion (contact us).

Last updated 2026-09-28 · Report an issue with this page