Guide
Org API keys are not browser cookies.
RenderMac separates browser sessions (D1 website identity), organization API keys (buyer automation), host enrollment codes, and device tokens. Never put API keys in frontend storage.
- Browser session — HttpOnly cookie for app/provider dashboards.
- Organization API key — server-side automation against the control plane.
- Host enrollment code — one-use pairing for Macs.
- Device token — narrow Keychain credential after claim.
Identity boundary docs live in the repo AGENTS.md and WEB-IDENTITY guide. Marketing takeaway: your SaaS backend holds the org key; the browser never does.
For developers · Create beta account · Security.
Join the free buyer beta
Developers and buyers can create an account and use available beta capacity without charges. Capacity is limited and there is no production SLA.
Create free beta accountOne RenderMac account can use both dashboards. See the unpaid beta terms.