Skip to main content

Developer Portal Service — Domain Model

Version: 1.0 Status: Draft Owner: Product + Developer Relations (DevRel) Last Updated: 2026-04-20 Companion: SERVICE_OVERVIEW · API_CONTRACTS · EVENT_SCHEMAS


1. Intent​

Define the aggregates, entities, value objects, and invariants that the Developer Portal owns. The portal is the developer-facing surface for documentation, sandbox, self-serve API key management, consumption analytics, SDK distribution, and the managed Verify API. Identity and key secret material remain in auth-service; this service stores only metadata and orchestration state.

2. Aggregates​

  • DeveloperAccount — TBD (linked 1:1 with auth-service Account; profile, default tenant, locale, MFA preference)
  • ApiKey (metadata) — TBD (env, scopes, label, last-used; secret stored in auth-service)
  • SandboxSession — TBD
  • VerifySession — TBD (verificationId, channelOrder, currentChannel, attempts, expiresAt, codeHash)
  • VerifyTemplate — TBD
  • SdkRelease — TBD
  • DocsArticle — TBD

3. Entities​

  • TBD

4. Value Objects​

  • Channel — SMS | VOICE | WHATSAPP | EMAIL — TBD
  • Locale — en | ps | fa — TBD
  • Environment — SANDBOX | PRODUCTION — TBD
  • VerifyState — PENDING | DELIVERED | APPROVED | FAILED | EXPIRED — TBD

5. Invariants​

  • API key secret material is never persisted in devportal Postgres — only prefix + metadata. TBD
  • Verify code is stored as HMAC-SHA-256(code, server-pepper), never plaintext. TBD
  • A VerifySession cannot transition out of a terminal state (APPROVED | FAILED | EXPIRED). TBD
  • attempts is monotonically non-decreasing within a session. TBD

6. Domain Events​

  • devportal.key.created.v1 — TBD
  • devportal.key.revoked.v1 — TBD
  • devportal.verify.requested.v1 — TBD
  • devportal.verify.delivered.v1 — TBD
  • devportal.verify.approved.v1 — TBD
  • devportal.verify.failed.v1 — TBD
  • devportal.verify.spend_cap_hit.v1 — TBD
  • devportal.sdk.released.v1 — TBD
  • devportal.sdk.downloaded.v1 — TBD

7. Aggregate Boundaries​

TBD (write boundaries, transactional consistency surfaces, references to other aggregates by id only).

8. Glossary​

TBD