Skip to main content

Projects

Projects are the boundary around one target app in Qodex. A project owns its chats, scenarios, scripts, findings, environments, memory, API keys, members, and BYOK credentials. Keeping these objects project-scoped prevents data and access from crossing between apps or teams.

What belongs to a project

Every meaningful object in Qodex is project-scoped: chats, scenarios, scripts, findings, test runs, environments, collections, memory, API keys, and BYOK credentials. Cross-project access is not possible from the agent or the API. Each project has its own members and roles, its own API keys for webhooks and CI, and its own environments with target URLs, auth profiles, and constraints for staging, production, preview, or any other environment.

Workspaces

A workspace is the set of projects you can reach from the project switcher. All data is isolated per project.

Members and roles

Users sign in with email, Google, or GitHub. Enterprise projects can also use Microsoft SSO. A user joins a project with a role, and membership scopes what the user can read and do in the project. The project switcher at the top of the left navigation lists every project the user belongs to.

Project-scoped routes

The web app uses /p/{slug}/... for everything project-scoped:
The API mirrors this. A link without a project slug opens that page in your only project, or asks you to pick one when you belong to several.

Environments

A project can have many environments. Each environment carries:
  • A name and a base URL (and apiBaseUrl if different).
  • Auth: static auth_token, or api_login_config (HTTP login + JSONPath token), or ui_login_steps (Playwright drives login, captures storageState).
  • Constraints: read-only, max requests per second, allow destructive tests, allow security testing.
The same scenario runs against any of them by passing ${baseUrl}, ${apiBaseUrl}, ${authEmail}, ${authPassword} and the SCREAMING_SNAKE variants. Switching environments is one click.

BYOK

Bring-your-own-key credentials are stored at the project level. Today each project can add its own OpenAI key or connect its own ChatGPT subscription. Anthropic and Google keys are on the roadmap. Qodex takes zero margin on AI spend. Platform-funded usage runs on Qodex capacity and counts against the project’s plan caps. Usage on your own key or your own ChatGPT subscription never does. See Usage and cost caps.

Cost tracking

Every LLM call is logged with the project, provider, model, input and output tokens, latency, outcome, cost, and which credential paid for it. Open Usage from the account menu to see how much of the plan the project has used.

When to use it

  • Use one project per target app. A monolith with one frontend and one API is one project.
  • Create a separate project per environment only when the apps differ enough, such as different auth or domains. Otherwise use one project with multiple environments.
  • Create a separate project per customer if you run a multi-tenant agency setup.

When not to use it

  • Splitting a single app into projects per team. Use chats and tags inside one project instead.
  • Sharing scenarios across projects. Today scenarios are project-bound. To share, export and re-import.

On the roadmap

Planned: organization-level rollups across projects for activity, spend, and administration.
Planned: Anthropic and Google keys for bring-your-own-key.

Memory

Project-scoped knowledge.

Environments

Project-scoped targets and auth.

Members and roles

Who can do what in a project.

BYOK

Per-project key management.