Learning slice — BFF reference
Two authorization axes against the assetera realm: the user token (Tokens, proxied to the marketplace API) and a service account (via the Keycloak Admin API — e.g. reading your 2FA enrolment on Account & security). The browser never holds a token — the BFF does.
What to try
- Tokens — any signed-in user sees their tenant's listings;
marketplace-admincan add / toggle / delete. - Dashboard — your account, wallet, KYC status and Account & security (password / 2FA).