Anything typed here is merged into the extraction pass and is used to resolve values the photograph leaves unclear.
Sealing writes the JPEG to your own R2 bucket and the index row to your own D1 database. Once sealed, the record can never be edited or deleted through this API.
| ID | Date | Vendor | Category | Sub-category | Total | VAT | Vault folder | File | Size | Flags | Actions |
|---|---|---|---|---|---|---|---|---|---|---|---|
Connect a workspace to stream its vault. | |||||||||||
| Client ID | Account name | State | R2 bucket | Token | Last verified | Actions |
|---|---|---|---|---|---|---|
Enter the admin key and load the registry. | ||||||
Cloudflare Access proves who a caller is. This table decides which vaults that identity may open. An identity with no row here reaches no data, however valid its token.
| Principal | Role | Capabilities | Granted by | Actions |
|---|---|---|---|---|
Connect a workspace, then load its grants. | ||||
Runs client_schema.sql inside the client's own D1 cluster: documents ledger, audit trail, folder view and the immutability triggers. Safe to re-run.
- Images are written to the client's own R2 bucket, never to LeoCore storage.
- Index rows are written to the client's own D1 cluster.
- The coordinator database holds connection profiles only.
- Images are streamed back through an authenticated proxy; the bucket is never public.
- Revoking the scoped token severs LeoCore's access immediately and completely.