Mountable
Sign in

Overview

Mountable is a filesystem your agents can mount anywhere. A sandbox runs mountable mount and gets an ordinary POSIX directory backed by a Mountable filesystem; files written there outlive the sandbox and can be mounted again somewhere else.

How it fits together

  • An organisation owns filesystems, members, groups, and API keys.
  • A grant lets a member, group, or API key mount one whole filesystem, read-only (ro) or read-write (rw).
  • A mount session is created by your backend (with an API key) or by a person (with mountable login). Creating it returns a one-time ticket.
  • The sandbox exchanges the ticket for a short-lived session certificate. That certificate is the only credential the sandbox ever holds.

What stays out of the sandbox

API keys and login tokens never enter a sandbox. The sandbox holds exactly one credential, scoped to one filesystem and one mode, with an expiry and live revocation: no new operation is admitted more than 15 seconds after you revoke a session.

Next steps