Settings
Members and roles, project and environments, end-user authentication, widget branding, audit log.
Organization
Members with role selects (owner rows are locked) and a Remove button. Invite by email with a role: admin (settings, keys, secrets), developer (agents, tools, workflows), viewer (read-only). Owners can do everything and are the only ones who can change roles.
Project
Name (saves on blur), slug, the two environments with their ids, the data region (Automatic today; EU and US pinning planned), and memory retention: how many days recall snippets and remembered facts about a user are kept (default 180; 0 keeps them until the user is forgotten). A nightly job prunes older ones; conversation summaries stay with their conversations. See Memory.
End-user auth
How the runtime verifies the JWT your app passes to authenticate(token:):
| Mode | Fields |
|---|---|
| HS256 shared secret | Secret (from Secrets) |
| JWKS URL (RS256/ES256) | JWKS URL |
| Anonymous only | none; tokens are rejected |
Optional Issuer and Audience are enforced when set. Anonymous visitors (identifyAnonymous) always work.
Widget branding
Colours (primary, on-primary, surface, background, text, muted text), radius, font family, agent display name, launcher position and icon. Sent to the SDK in the session bootstrap; KletsoTheme.fromServer applies it. A live preview card shows the header, a bubble, a product card and the launcher with your values.
Audit log
Every mutation (publish, key created, secret rotated, member invited, …) with time, actor and summary.
Danger zone
Reset demo data (in-browser demo mode only) and project deletion (contact us).