Selected for the next certification batch. Live verification has not yet started. The page shows what we intend to investigate, not what we already read.
Intended capabilities
What we want to monitor
Documentation feasibility verdict: LIMITED. Responses can expose consumed daily/monthly quota headers, but passive reads require full_access. A sending_access key is send-only and no documented dry-run exists, so there is no safe monitoring-only credential. Do not request full_access without explicit security review.
How to connect
Connection model
Auth
Personal access token(not yet verified)
A scoped token with read-only permissions. We never ask for write or admin scopes. Rotate or revoke the token from the provider at any time.
Boundaries
Plan, usage, and limits (the data you see in the dashboard)
Account or organization name (so you can pick the right one)
×Database rows, customer data, application source, env vars
×Anything write or admin scoped
Capability manifest
What BeforeRed can read
Every capability reflects the real state of the provider. The V0 reconciliation harness (PRD §9) is the only thing that promotes a capability to certified.
Authentication
BeforeRed can connect to the provider at all.
Supported
OAuth
OAuth is available, with a documented flow.
Not available
Account discovery
BeforeRed can list the user's account or organization.
Not available
Project discovery
BeforeRed can pick a specific project or service to monitor.
Not available
Plan detection
BeforeRed can read which plan you are on.
Not available
Free-plan support
Useful signal is available on the Free / Hobby tier.
Supported
Usage monitoring
Current usage values for the metrics you care about.
Not available
Historical usage
BeforeRed can read past values, not only current usage.
Not available
Limit retrieval
BeforeRed can read the currently applicable limit.
Supported
Cost monitoring
Spending can be attributed to specific projects or services.
Not available
Token refresh
OAuth tokens are refreshed automatically without re-auth.
Not available
Disconnect
The user can revoke access from the provider side and we know.