Getting Started

Tutorial: Building with CleaveDB

Authenticate (AUTHENTICATE)

The AUTHENTICATE command sets or switches the active user identity for the current session. In CleaveDB, this user context governs access control policies, rate limits, audit logs, and multi-tenant namespace isolation.

Setting caller identity

Authenticate using a plain username string or a bucket-qualified document identifier:

CleaveQLExample · Authenticate session
AUTHENTICATE AS "david"

Or with the qualified document notation:

CleaveQLExample · Qualified document identity
AUTHENTICATE AS "users:david"

Once authenticated, the session adopts the identity david. Any policy evaluating @user_id or matching bond ownership (e.g. bonded as "owner" to my user_id) uses this identity automatically.

System impact of authentication

Switching the authenticated user alters several core database behaviors:

  • Security Gate Resolution: DLS policies automatically re-evaluate permissions against the new user ID.
  • Rate Limits: The session binds to the rate limit quota configured for the user's assigned role.
  • Audit Trail Attribution: When AUDITED buckets record modifications, the tenant and user fields in the _audit_* records record the active caller.
  • Webhook Context: Outgoing Change Data Capture (CDC) HTTP requests include the user identity in event payloads.