# Partner workspace and access status

> Use one dashboard for Hosted API and installations, select Sandbox or Live, and resolve approval, licensing and credential blockers.

## Where do I see API access and installations?

Sign in with your verified email. The Sandbox and Live dashboards show **API access** and **Installations & licenses** separately. You can save a personal Hosted API/OnPrem/Both preference; this changes your workspace preference, not your organization's authority.

The API section shows Hosted Live eligibility, approval status and the next required action. The installation section shows requests, licenses, access level, expiry, domain verification, identity enrollment and credential retrieval. Older licenses without a linked application can also appear. The summary returns at most 50 installation entries; ask operations if an expected older entry is missing.

## Why is Live unavailable?

Use the displayed next action. An active key alone does not establish production approval. A suspended organization, blocked Hosted access, inactive parent credential, membership restrictions or commercial controls can prevent access. A failed selector check leaves you in the current environment.

| Status or error code                                            | Meaning                                                                        | Next action                                                                                               |
| --------------------------------------------------------------- | ------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------- |
| `HOSTED_LIVE_APPROVAL_REQUIRED`                                 | No explicit Hosted Live approval                                               | Ask partner operations to review Hosted Live; continue in Sandbox                                         |
| `HOSTED_LIVE_BLOCKED`                                           | An administrator blocked Hosted Live                                           | Request review with the reason and request reference                                                      |
| `PARTNER_INACTIVE`                                              | Organization or parent credential is inactive                                  | Ask operations to restore eligible access                                                                 |
| `EVALUATION_PRODUCTION_BLOCKED`                                 | The applicable evaluation/legacy access policy denies production               | Complete the appropriate production approval; changing the key prefix cannot help                         |
| `PRODUCTION_ACCESS_EXPIRED` or `PRODUCTION_ACTIVATION_INACTIVE` | Legacy direct access depends on an installation grant that is no longer active | Ask operations to review the legacy activation and Hosted approval                                        |
| `PRODUCTION_CONTRACT_INACTIVE`                                  | Required commercial agreement is not active                                    | Ask operations to review the contract and applied entitlements                                            |
| `INSTALLATION_LIVE_APPROVAL_REQUIRED`                           | The current installation context cannot enter Live                             | Complete installation production readiness; use separately approved Hosted access through its own context |

These are access outcomes, not a promise that every endpoint returns the same status/body. Use the actual HTTP response and [error contract](/partners/docs/errors).

## Does an expired installation disable my Hosted API?

For organizations with an explicit approved Hosted Live decision, the lifecycles are independent: installation expiry/revocation blocks installation calls while approved direct Hosted access remains subject to its own controls. Older organizations without an explicit Hosted decision retain their legacy checks, including installation-linked production grants. There is no automatic migration that grants new rights. Ask an administrator to review the intended access model.

Installation evaluation cannot mint a Live console session, even if the organization also has Hosted Live approval. Installation requests still enforce their license, exact domain, signed identity proof and tenant membership. Identity enrollment means a device identity was registered; it is not evidence that the full installation passed readiness checks.

## How does the portal select an environment?

These are **signed-in portal operations**, not API-key integration endpoints. Obtain a fresh Firebase ID token through the authenticated portal; never copy tokens into tickets or source control. The following Bash examples assume `FIREBASE_ID_TOKEN` was securely supplied in your process environment.

```bash
curl --fail-with-body 'https://mystocks.africa/api/v1/partner/me?workspace=1' \
  -H "Authorization: Bearer $FIREBASE_ID_TOKEN"
```

```bash
curl --fail-with-body -X POST 'https://mystocks.africa/api/v1/partner/me' \
  -H "Authorization: Bearer $FIREBASE_ID_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{"action":"select_environment","environment":"live"}'
```

Successful selection returns `navigateTo`: `/partners/dashboard` for Live or `/partners/sandbox` for Sandbox. Failure returns an error rather than granting access. This action does not mint credentials or modify approvals.

```bash
curl --fail-with-body -X POST 'https://mystocks.africa/api/v1/partner/me' \
  -H "Authorization: Bearer $FIREBASE_ID_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{"action":"deployment_preference","deploymentPreference":"both"}'
```

The preference is saved for the authenticated user and audited. Supported values are `hosted`, `onprem`, `both`; environment values are `sandbox`, `live`. These portal actions do not use the partner integration idempotency mechanism.

## How do I finish onboarding or renew access?

1. Choose your [deployment model](/partners/docs/deployment-options) and submit the correct application or installation request under your verified account.
2. Review the dashboard's next action. Operations must match the application to the correct organization; another organization's approval is not transferable.
3. For Hosted Live, wait for the explicit decision and use the proper production credential. For OnPrem, follow [activation](/partners/docs/onprem-activation), retrieve the credential once and verify the installation.
4. For expired offers, renewal, release compatibility or registry access, use the installation workspace's specific action and [operations guide](/partners/docs/onprem-operations).
5. Contact support with the request/license reference, timestamp, error code and sanitized health evidence. Never include raw keys, private identity files, passwords or account tokens.

## What does administration change?

Administrators review Hosted approval separately from licenses in **Access & deployments**. Hosted decisions require a review reason, explicit confirmation and authorized recent administrator authentication. The decision updates shared authorization, records audit evidence and queues a notification. An email being queued is not proof of inbox delivery or an operational installation.

Trading, funding, payout and reconciliation remain separate workflows with their own permissions, balances, eligibility and settlement state. Approval or switching to Live does not fund a wallet, clear KYC, settle an order or waive limits. See [operational controls](/partners/docs/operational-controls) and [daily reconciliation](/partners/docs/daily-reconciliation).
