Developer hub
Authentication
Match the credential to the surface. GoldShore never asks you to paste a private token into public forms, documentation, or client-side code.
No credential
Public routes
Documentation and explicitly public status resources can be read without an account.
Cloudflare Access
Operator workspace
Human operators authenticate at the protected admin origin. Authorization remains enforced by server middleware.
Bearer or provider credential
API clients
Use only credentials issued for the specific integration and environment. Send secrets in headers, never query strings.
Access service token
Service identities
Approved machine-to-machine clients may require both CF-Access-Client-Id and CF-Access-Client-Secret headers.
