Dexby

Project settings

Manage API keys, your team, the Connect page, logs, usage, the audit trail and deletion.

A project is an isolated environment with its own API keys, auth configs, users, connections, webhooks and logs. Nothing is shared between projects. A common layout is one project per product or environment, such as support-agent and support-agent-staging. Every page below is in the dashboard.

API keys

Configure → API keys → Create key. Give it a Name and choose Expires (Never, 30 days, 90 days or 1 year).

  • The key (dx_ plus 64 hex characters) is shown once. Dexby stores only a SHA-256 hash.
  • A key belongs to one project and can call every tool for any user id, so keep it on your server.
  • Revoke stops the key at once.
  • To rotate: create a new key, deploy it, wait until the old key's Last used stops moving, then revoke the old one.
dexby.ts
import { Dexby } from '@dexby.ai/sdk'

const dexby = new Dexby() // reads DEXBY_API_KEY

Team

The team belongs to the organization, not to one project. Open the organization from the switcher in the top bar, then Team → Invite members. Enter one or more emails separated by commas, pick a Role, click Send invites. Invitation emails are not sent yet: copy the link from Pending invitations and share it.

RoleCan
ownerEverything, including deleting the organization.
adminManage projects, keys, connectors and members.
memberRead every project in the organization. Change nothing.

Roles apply to every project in the organization. Members cannot create keys, change settings or run the Playground. You cannot change your own role. Leave takes you out of the organization; the last owner must make someone else an owner first.

Connect UI

Configure → Connect UI brands the hosted Connect page that connect links open. Changes go live on Publish; Discard reverts.

SettingEffect
Logo, App name, AccentBranding. App name defaults to the project name.
Support URL, Privacy policy URLFooter links.
Allowed redirect URLsWhere connect links may send users back. See below.
Show data types on permissionsShows General, Personal data or Health data next to requested access. On by default.
Let users manage their connectionsLets users rename or disconnect their accounts. On by default.

Allowed redirect URLs takes one URL per line, up to 20. Each is https, or http on localhost, 127.0.0.1 or [::1]. A trailing * allows any URL with that prefix. Empty allows any https URL. A connect link whose redirectUrl is outside the list is refused.

Logs and usage

  • Operate → Logs: the latest 100 requests (every /v1 call and Playground run), refreshed every 5 seconds. Each row keeps time, tool or path, user, status, classification and duration. Request bodies, query strings and responses are kept only when the project's request logs are set to Details and payloads.
  • Configure → Settings → Usage: this calendar month in your time zone: requests, tool executions, failures, bytes in and out, and median duration. Billing is not enabled.

Request logs

Configure → Settings → General → Request logs decides what Dexby keeps about this project's requests. Owners and admins change it; every change is recorded in the audit log.

ChoiceWhat is kept
NothingNo request logs. Calls run as usual, and Operate → Logs says request logs are off.
Request detailsThe default. Tool, status, timing, sizes and error code, for 30 days. No request bodies, query strings or responses.
Details and payloadsRequest details, plus each tool call's request body, query string and response, for 7 days. The details stay for 30 days.

With Details and payloads:

  • Content of general tools (standard) is kept. Content of personal data tools (pii) is kept only when Include personal data is on. Content of health data tools (phi) is never kept.
  • Passwords, tokens, API keys and other secrets are replaced with <redacted> before anything is stored. A field or query parameter counts as a secret when its name says so: password, secret, token, api_key, authorization, cookie, credential, signature and similar names.
  • Raw requests through the proxy are treated as personal data.
  • Playground responses are never kept.
  • Only owners and admins can read a stored payload, from the log's detail. Each read is recorded in the audit log.

Moving down deletes what the new choice does not keep, in the same step as the save: Nothing deletes every request log of the project, and Request details deletes every stored payload. Moving up only saves; it keeps nothing about earlier calls. Turning Include personal data off stops new personal data from being kept; payloads already stored stay until they are 7 days old.

Usage counts requests, executions, failures and bytes whatever the choice, and audit records are written either way. Median duration and one user's usage come from request logs, so they cover only calls that were logged.

Health data

Health data is coming soon. Until it launches, health data tools (phi) do not exist in any project. They are left out of the catalog's tool lists and action counts, the Playground, sessions and MCP endpoints, and the API answers a call to one with 404 TOOL_NOT_FOUND, as for any unknown tool. Connectors still show; only their health data tools are hidden. Creating or updating a project with handlesHealthData: true fails with 400 VALIDATION_ERROR.

Audit trail

Configure → Settings → Audit log shows the latest 200 records, filterable by action, actor or target. Records hold ids, names and counts, never payloads or secrets.

The log is a SHA-256 hash chain per organization. To check it, a signed-in member calls:

Verify the chain
GET /api/dashboard/projects/:projectId/audit/verify

It returns { "data": { "valid": true, "count": 311 } }, or valid: false with brokenAt. This route uses the dashboard session, not an API key. :projectId is the Internal ID on Configure → Settings. See Security.

Delete a user or project

Both are permanent and support right-to-erasure requests.

  • User: Operate → Users → a user → Erase user. Removes the user's triggers, credentials, connections and sessions, deletes the payloads stored for their calls, and removes their id from request logs.
  • Project: Configure → Settings → Delete project, then type the slug. Erases every credential and secret first, then the project and everything in it. Its API keys stop working at once.

If any credential cannot be erased, the request fails with CREDENTIAL_UNAVAILABLE and nothing is removed. Audit records are kept.

On this page