Dashboard

Managing Projects

Create, configure, and manage Checkpoint projects for AI agent detection

What Are Projects?

A project in Checkpoint represents a single property (website, API, or application) that you want to protect. Each project has its own:

  • Project ID and API Key: Credentials for SDK integration
  • Detection settings: Classification preferences and sensitivity
  • Enforcement policies: How to handle detected agents
  • Analytics: Detection data, trends, and reports
  • Team access: Who can view and manage the project

Prerequisites

  • A Checkpoint account. If you don't have an organization yet, you'll be prompted to create one the first time you sign in.

Creating a Project

  1. Sign in to the Checkpoint dashboard
  2. Select your organization (or create one)
  3. Click New in the top navigation, then select New project
  4. Enter:
    • Project Name: A descriptive name (e.g., "Production Website")
    • Site URL: The domain you want to protect (e.g., https://example.com)
  5. Click Add Domain

The project is created immediately, and the same dialog expands in place to show the installation steps (toggle them with Hide installation code / Show installation code). Opening the full Installations page (legacy name: the Deployment tab) for the same integration instructions is a separate action you can take any time afterward.

You can create multiple projects per organization. Use separate projects for different environments (production, staging) or different properties (website, API, mobile).

Project Credentials

Every project has two credentials:

CredentialPurposeWhere to Use
Project IDIdentifies your projectPixel, Beacon, Middleware, Gateway
API KeyAuthenticates API requestsServer-side integrations, Govern middleware

Find both under Installations in the dashboard. See Credentials for the full walkthrough.

Keep your API Key secret. Never expose it in client-side code. The Project ID is safe to use in client-side integrations (Pixel, Beacon).

Project Settings

General

Configure basic project properties:

  • Project Name
  • Site URL
  • Detection retention (days): how long detection events are kept before being purged (minimum 7 days, default 365)

There's no environment selector on a project. Use separate projects to distinguish production, staging, and other environments (see Creating a Project).

Detection

Detection behavior (confidence thresholds and blocking rules) isn't configured from Project Settings. It lives under Enforce → Policies. See Policies to configure it.

Enforce

Set up active enforcement:

  • Gateway: Add DNS-based enforcement domains. See Gateway.
  • Middleware: View integration code for Next.js or Express. See Middleware.
  • Policies: Configure enforcement rules. See Policies.

Policy → Auth (Govern)

Configure KYA-OS governance on the Policy → Auth page: one three-card journey (Auth → Consent → Success):

  • Auth methods: Add OAuth or credential providers agents authenticate with
  • Consent branding: Customize the consent and success screens agents' users see
  • Tool coverage: Assign each discovered tool an auth method (per-tool delegation requirements: OAuth, credentials, or consent-only)

See Govern for details.

API Keys

Your Project ID and API key are managed under Installations, not on a Project Settings tab. See Credentials for where to find and use them.

Deny List (Legacy)

Manually block specific detected agents through the legacy structured policy layer (superseded by Cedar forbid rules authored in Compose):

  • Block by agent DID: an exact match against the request's delegation DID
  • Block by detected agent name: a case-insensitive substring match (not a raw user agent string match)

The deny list runs after detection, and after path rules and the allow list have already been evaluated. It is not a pre-detection fast path or a priority override. See Deny List: Evaluation Order for the full pipeline.

Installations (Legacy Name: Deployment)

Installations provides integration instructions for each detection method:

  1. Pixel: Copy the script tag, GTM, or React snippet
  2. Beacon: npm install command and initialization code
  3. Middleware: Next.js or Express setup code
  4. Gateway: DNS record configuration, see Gateway

Pixel and Beacon snippets are client-side, so they include your Project ID only, never the API key. Middleware snippets include your API key too when one is available. Gateway needs no code snippet at all; set it up from the Gateway settings page. See Credentials if you need these values elsewhere.

Team Management

Checkpoint has two separate role systems: organization roles (who belongs to the organization) and project access levels (what they can do on a specific project).

Organization roles

  1. Navigate to organization Settings → Team
  2. Invite members by email
  3. Choose a role for the invite:
    • Admin: can manage organization settings and members (everything except transferring ownership)
    • Member: can access organization projects and basic features

Owner isn't an invite option. It's assigned by transferring ownership of the organization.

Project access levels

Project access can override organization permissions on a per-project basis, set from that project's own Team settings:

  • Admin: can manage project settings and members
  • Editor: can view and edit project data
  • Viewer: can only view project data

A project's owner always has full control over that project, regardless of access level.

Multiple Projects

Common multi-project setups:

ProjectPurpose
Production WebsiteMain site protection
StagingTest detection before production
APIProtect API endpoints separately
Marketing SitePixel-only detection for marketing

Each project has independent settings, policies, and analytics. Use the project switcher in the dashboard sidebar to navigate between them.

Next Steps