Tutorial: Building with CleaveDB
Login Secrets
WITH SECRET is for a parent account that needs to create another user within its own tenant. Picture the authenticated account as a boarding house: it can register a new resident, give that resident a separate login, and keep the relationship anchored to the parent tenant. Use this when an organization or customer account needs to add its own members, staff, or other sub-users.
POUR INTO users "bob" {"name": "Bob", "role": "viewer"} WITH SECRET "<password>"What this command creates
- The parent account: run the command while authenticated as the account that owns the tenant space—the boarding house in this picture.
POUR INTO users "bob"and the JSON: create Bob’s user document in theusersbucket, with profile fields such asnameandrole.WITH SECRET: register Bob as a sub-user under that parent account and create the authentication entry that lets him sign in.
Where this fits in an application
Consider a business customer that manages its own team. The business account is the parent tenant; when it adds Bob, the JSON stores his application profile and WITH SECRET provisions his sub-user login within that parent’s tenant. Bob is a distinct user, but he is not created as an unrelated top-level tenant. This is the difference between opening another boarding house and giving a new resident a room in the one that already exists.
The user profile remains ordinary document data that your queries can find or update. The password is handled separately through the authentication entry, where CleaveDB stores its hash rather than a plain-text password. Keeping identity, profile data, and the parent-tenant relationship clear makes this command easier to reason about as an application grows from one account to many teams and members.
