Onboarding
Willkommen. Wenn Sie diese Seite lesen, haben Sie Zugriff auf das xander Demo Portal. Sie sind also bereits als Guest-User in unserem Entra-ID-Tenant eingeladen. Hier erklären wir die zwei Credentials, die Sie benötigen, wofür sie da sind und was zu tun ist, wenn etwas nicht funktioniert.
Zwei Credentials, zwei Zwecke
Die Arbeit mit xander betrifft zwei verschiedene Identitäten. Sie sind unabhängig voneinander und werden in unterschiedlichen Kontexten eingesetzt.
| Credential | What it is | What you use it for |
|---|---|---|
| Your personal Entra ID account | Your normal work account at your own employer, invited as a B2B guest into XWare's xander Entra ID tenant. | Signing in to this demo portal in your browser, reading documentation, trying endpoints with the "Test Request" button. |
| A Service Principal (Client ID + Client Secret) | A machine identity provisioned in XWare's Entra ID tenant, granted permission to call the xander API. | Authenticating your application's API calls server-to-server (Client Credentials flow). Your backend code uses these credentials to obtain an access token, then calls xander API endpoints with that token. |
Your Service Principal is issued to your organisation, not to you personally. It is the billing pivot point. All API usage from your Service Principal is attributed to your organisation's account.
How you receive your credentials
Your personal Entra ID account is invited via a standard Microsoft B2B guest invitation. You'll receive an email from Microsoft on behalf of XWare Pulse AG, click the link, accept the terms, and you're in.
Your Service Principal credentials (Client ID + Client Secret) are delivered separately and personally by your xander contact at XWare Pulse. The exact delivery method depends on what works for you (encrypted message, secure vault link, video call). Treat the Client Secret like a production password from day one. Store it in your secret manager, never commit it to source control.
Your Service Principal grants access to our production environment. We do not provide separate sandbox, dev, or test environments to customers because the API is stateless. every call you make, including testing and experimentation, is a real production call and will be billed normally. Be deliberate when looping over endpoints, especially audio transcription and large document extraction, as those are the most expensive calls.
First steps after receiving your credentials
- Go to API Reference.
-
Paste your Client ID and Client Secret into the auth card above the documentation. They
live only in your browser's memory. They are not stored in
localStorage,sessionStorage, or sent anywhere except our token proxy. -
Pick a low-cost endpoint like
POST /prompt/informationextractionwith a small text payload, click "Test Request", and confirm you receive a 200 response. Your first call goes through the entire auth chain (token fetch + bearer header injection), so a successful response confirms your setup works end-to-end. - Read the Cookbook for the typical workflows we recommend (audio intake with catalog reduction, document extraction, long-form meeting transcription).
-
Read Limits & Quotas so you know how
the API tells you when you're approaching your rate limit, and how to handle
429responses gracefully in your application.
Secret rotation
Your Client Secret has a fixed lifetime of 365 days. We rotate proactively. you don't need to track expiry yourself. Here's the process:
- 30 days before expiry, your xander contact sends you a new Client Secret. Both the old and the new secret are valid simultaneously during this 30-day overlap window.
- You migrate at your own pace within the overlap window: deploy the new secret to your application, verify everything still works, then discard the old one.
-
At the expiry date, the old secret stops working automatically. If
you haven't migrated, your application starts receiving
401 Unauthorizedresponses.
What if my secret is compromised?
Reach out to your xander contact at XWare Pulse, or write to xander@xwr.ch, immediately. We will revoke the compromised secret and issue you a new one out-of-band. Do not wait for normal rotation.
Getting help
For anything we haven't covered here. contractual questions, compliance documentation, adding new developers from your organisation, additional Service Principals for separate applications, increasing your rate limits. reach out to your xander contact at XWare Pulse. If you don't have one to hand, xander@xwr.ch reaches our central inbox and we'll route you to the right person.