Per-org credential resolution with a per-credential token cache. Credentials come from Settings for any org; environment variables remain an optional bootstrap path for the original tenant.
Also called: SmartBuild credentials · connect SmartBuild · per tenant SmartBuild · SmartBuild login
- 1Tokens are cached keyed by username with a 23-hour expiry, so each tenant's login is cached separately.
- 2SmartBuild tokens can be revoked upstream (password rotation, admin force-logout, server reset) while the local cache still thinks they are valid, so a 401 invalidates the cache, re-logs in and retries exactly once.
- 3A 500 from a read endpoint is retried once after a short backoff, because the API has shown intermittent 500-empty responses for calls that succeeded moments earlier.
- 4An org with no credentials gets an empty-but-valid response shape on reads (an empty project list, a null estimate) and a 503 on writes — never another tenant's data.
- 5The login is quirky and can return non-2xx with a token body, so the proxy warns and proceeds rather than throwing.
Each shop's SmartBuild account is its own, and connecting one used to be something only a developer could do. Credentials are entered and managed in settings by the shop itself, so adding or rotating a connection is not a deploy and not a support ticket. A company that has not connected anything sees an empty state and a working dashboard rather than an error, which matters because most of the platform has nothing to do with SmartBuild.
- Single-tenant integration configuration.
- Stale cached tokens replaying against a revoked session.
- Unconnected orgs seeing errors instead of an empty state.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →