01
Session JWT
Short-lived, SSO-backed. Carries tenant, team, and the claim set for the active desk.
Access · Claims
GitHub-style per-user tokens: short session JWTs for the suite UI, longer PATs for automation. Scopes are tenant- and team-aware — and they are what unlock catalog variants for a desk.
Mint UI wires to SSO (Okta, Google, X, OIDC / SAML IdPs) next. This page is the claims ↔ catalog contract operators will defend in review. Live subscribe minting for MoQ hangs stays on colorbars.dev/token.
Claims → catalog
Toggle scopes like a PAT. The catalog below is what those claims unlock for a team-scoped operator.
3 scopes · 3/6 variants
Live mint + SSO map IdP groups into tenant / team before these scopes apply. Desk lab: colorbars.dev/token · colorbars.dev/manifest
3/6 variants
| Title | Mode | Codec | Res | Region |
|---|---|---|---|---|
| Big Buck Bunny · live | live | avc1 | 1080p | US |
| Big Buck Bunny · instant replay | replay | avc1 | 1080p | US |
| moq.dev demo · live | live | avc1 | 720p | Global |
| Sports desk · AV1 ladder | live | av01 | 1080p | US |
| Linear channel · EPG window | live | avc1 | 720p | US |
| Mezzanine VOD · catalog publish | vod | avc1 | 1080p | Global |
No variants unlock — add catalog:read plus a geo window.
01
Short-lived, SSO-backed. Carries tenant, team, and the claim set for the active desk.
02
Create, label, revoke. Automation gets only the scopes an owner or team lead grants.
03
catalog:read plus geo / codec claims decide which aired and
replay rows appear — see Catalog.