Tessera docs

Launch Tessera

Launch

Core concepts

Permissions

Project roles and API key scopes that control who can change what.

Project roles

Role

Can do

Owner

Everything, including billing and deleting the project.

Admin

Manage environments, keys, members and production migrations.

Developer

Push to development and preview branches, deploy functions.

Viewer

Read schema, logs and metrics. No writes.

API key scopes

Keys are created per environment and carry scopes. Give each service the smallest scope it needs.

Terminal
npx tessera keys create --env production \  --name billing-worker \  --scope rows:read --scope rows:write

Rules still apply

Scopes decide which endpoints a key can call. Row-level rules still decide which rows it can see.

Was this helpful?

© 2026 Tessera, Inc.

Support

Status

Create a free website with Framer, the website builder loved by startups, designers and agencies.