Skip to main content
Reference

Direct gateway authentication

All API requests to Helix Cloud are authenticated with a Bearer token. Tokens are managed through the Helix dashboard. Include the token in the Authorization header of every request:
The SDK clients attach this header for you—set the key once with withApiKey (TypeScript), with_api_key (Rust and Python), or WithAPIKey (Go). See the cross-language Cloud connection example. Requests without a valid token are rejected at the gateway before reaching any database node. Token rotation and revocation take immediate effect from the dashboard. The Helix CLI does not use these application keys. Cloud CLI operations authenticate with a rotating WorkOS session, and Cloud CLI queries execute through the backend broker. Interactive MCP uses WorkOS OAuth for human sessions and the WorkOS agent registration flow for agents. The unified MCP endpoint also accepts workspace-owned service credentials with explicit project grants for query and customer administration tools. These sessions do not receive Cloud discovery or observability tools. Service credentials also support headless HTTP API calls. See the MCP access matrix.

Encryption

All traffic between clients and the gateway is encrypted in transit via TLS. Data at rest in object storage is encrypted using the storage provider’s server-side encryption.

Coming soon

These enterprise security features are on the roadmap and are not yet available. Contact founders@helix-db.com if your deployment depends on one of them.
  • Role-based access control. Fine-grained API key permissions beyond today’s read-only and read-write keys, for least-privilege credentials per service or environment.
  • SSO / SAML. Dashboard access through your identity provider (Okta, Azure AD, Google Workspace) with centralized provisioning and deprovisioning.
  • Audit logs. Per-request logging (timestamp, token identity, query name, source IP, response status) for compliance (SOC 2, HIPAA, GDPR) and forensic analysis.
  • AWS PrivateLink. A private endpoint in your VPC that routes to Helix Cloud without traversing the public internet, for network-isolation requirements in regulated environments.