Getting Started

Tutorial: Building with CleaveDB

Login Secrets

WITH SECRET is for a parent account that needs to create another user within its own tenant. Picture the authenticated account as a boarding house: it can register a new resident, give that resident a separate login, and keep the relationship anchored to the parent tenant. Use this when an organization or customer account needs to add its own members, staff, or other sub-users.

CleaveQLExample · Register a nested user
POUR INTO users "bob" {"name": "Bob", "role": "viewer"} WITH SECRET "<password>"

What this command creates

  • The parent account: run the command while authenticated as the account that owns the tenant space—the boarding house in this picture.
  • POUR INTO users "bob" and the JSON: create Bob’s user document in the users bucket, with profile fields such as name and role.
  • WITH SECRET: register Bob as a sub-user under that parent account and create the authentication entry that lets him sign in.

Where this fits in an application

Consider a business customer that manages its own team. The business account is the parent tenant; when it adds Bob, the JSON stores his application profile and WITH SECRET provisions his sub-user login within that parent’s tenant. Bob is a distinct user, but he is not created as an unrelated top-level tenant. This is the difference between opening another boarding house and giving a new resident a room in the one that already exists.

The user profile remains ordinary document data that your queries can find or update. The password is handled separately through the authentication entry, where CleaveDB stores its hash rather than a plain-text password. Keeping identity, profile data, and the parent-tenant relationship clear makes this command easier to reason about as an application grows from one account to many teams and members.