A portal is a promise: the catalog is current, the keys are behaved, the docs match the software. Portal scores all three — abuse per key, lag per docs page, risk per consumer — so the promise has a dashboard.
The sharpest alert on the overview is four words long: “unused but privileged.” A key idle for thirty days that can still write orders is the kind of thing a portal exists to surface — and this one does, by name.
portal.cedxsystems.com — live build
Runs on demo data. The demo workspace is a developer portal — the mechanics carry to any catalog you publish.
13.0M calls a dayacross 48 published APIs in the demo portal
102 of 220 docs pages stalestaleness is a queue, not a feeling
What it is
Three promises a portal makes, scored.
48 published APIs, docs lag on every row
The catalog shows version, stage, endpoints, apps and requests per day next to the number nobody prints: docs lag in days. The Orders API runs v2.4 at 920K requests a day with 48 days of documentation debt, and a deprecated MFA API still takes 624K.
Ver, stage, endpoints, apps, req/day per row
Docs lag in days, right next to traffic
Stable, beta and deprecated as filter chips
portal — screen-2
320 keys with an abuse score
Every issued key carries environment, plan, RPM, app count, abuse score and last-used date. A live checkout key on the Enterprise plan tops the table at 91; seventy-three keys have been unused for thirty days and stay listed.
Abuse ≥55 gets its own count — 38 keys
Rotated and revoked keys stay visible
Active, expiring, revoked, rotated filters
portal — screen-4
220 docs pages, 102 of them lying
The docs screen treats staleness as a defect with a number: lag in days and a broken-example count per page. A canary-probe SDK note is 109 days behind; a legacy-mobile auth page is 120. The rewrite queue is simply everything at stale ≥95.
Lag in days and broken examples per page
182 pages carry at least one broken example
Published, draft and archived states per page
portal — screen-3
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/portal.
portal.cedxsystems.com
01 — Overview
The portal's promises on one screen
Calls versus errors across the week, a health ring at 100% estimated availability, and alerts that arrive root-caused: a checkout key at abuse 91 with a geo spike and failed-auth burst; the Orders docs lagging v2.4 by 48 days; a partner key burning 86% of quota in a throttle storm.
API health mix: 23 healthy · 6 watch · 19 degraded
20 consumers above 80% of quota, listed
“Unused but privileged” is a named alert
02 — APIs
The catalog, with its debt visible
Forty-eight published APIs sorted by traffic, each with version and stage. The deprecated MFA API at 624K requests a day is the row that argues for this column layout: sunsetting is a traffic decision, and the traffic is printed.
920K req/day on the busiest row
Docs lag from 0 to 114 days in view
22 APIs need a docs rewrite, counted on the card
03 — Docs
Staleness measured in days
Two hundred twenty pages with API version, status, lag, broken examples and a stale score per row. The partner bulk-sync page disagrees with the changelog — the overview alert says so, with four broken examples attached.
Average lag 49 days across 94 contradictions
Stale ≥95 isolates the 102-page rewrite queue
Search by page, API or owner
04 — Keys
Abuse scored before it is outage
Three hundred twenty issued keys, 225 active, sorted by abuse. The columns are the investigation: environment, plan, RPM ceiling, apps using it, and the last-used date that separates forgotten from hostile.
38 keys at abuse ≥55, 20 at quota risk
73 unused ≥30 days — still listed, not swept
CSV of the filtered key view
Who runs it
Three roles keep the portal honest.
Roles, not references. We have no named customers yet, so nobody is quoted, credited or claimed as one — and this page ships without photography rather than with a synthetic frame.
API platform owner
Owns the 48-API catalog. The deprecated-but-busy rows — an MFA API at 624K requests a day — are their sunset plan.
deprecated · 624K req/day
Developer relations
Works the docs rewrite queue: 102 pages at stale ≥95, 182 with broken examples, oldest lag 120 days.
stale ≥95 · 102
Risk and abuse
Watches the 38 high-abuse keys and the 20 consumers leaning on their quota — before either becomes a pager.
abuse ≥55 · 38
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
13.0Mcalls per day48 published APIs, +4.2% on the card
320keys issued225 active · 73 unused ≥30 days
102stale docs pagesof 220 — the rewrite queue is stale ≥95
38high-abuse keysscored ≥55, with the top at 91
Highest-abuse keys, from the risk tableabuse score · plan printed per row
Live checkout key · Enterprise plan91
Partner sync key · Partner plan84
Staging partner key · Sandbox80
Legacy mobile key · Internal78
API health mix — 48 in cataloghealthy 23 · watch 6 · degraded 19
Healthy · 23
Watch 6 · degraded 19
Docs staleness102 of 220 pages at stale ≥95
102
Stale ≥95 · 102 pages
Current enough · 118
How it runs
A consumer's life on the portal, in order.
01
Publish
An API ships in the catalog with a version and stage — the Orders API is on v2.4, stable, production grade, at 920K requests a day.
02
Key
Consumers register apps and draw keys with plans and RPM ceilings; 320 issued, 225 active, each one scored.
03
Watch
Abuse scoring flags the 38 keys behaving badly — geo spikes, failed-auth bursts, off-hours patterns — with the signal named per alert.
04
Rewrite
Docs staleness is measured in days per page, and the rewrite queue is the 102 pages at stale ≥95 — owned, like the catalog.
One record
The portal is the door. The estate is the house.
A portal publishes what the rest of the estate builds and answers what it cannot. The screens share one workspace and one Ask AI button.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Portal is not generally available. What opens today is the live build on demo data — Northline's developer portal is the software's demo workspace, not a customer.
The demo workspace is a developer portal. If your portal is a customer self-service one, the mechanics — catalog, access, staleness, abuse — carry; the nouns differ, and this page will not pretend otherwise.
Abuse scores flag behaviour for a person to act on. The demo shows scoring and queues, not automated revocation, and we do not claim auto-blocking here.
The 100% on the health ring is the portal's own estimated availability for the demo window. It is not an SLA, and it is not a claim about your uptime.
No audit or compliance certification has been issued. What we can evidence about hosting and access is on the security page.
Yes. Every screenshot is a capture of the running build, open at /app/portal. It runs on demo data — the workspace on the chrome is the demo tenant.
What does the abuse score actually read?
The signals are named in the alerts: geo spikes, failed-auth bursts, off-hours patterns, quota burn. The keys table shows the score next to environment, plan, RPM and last-used, so a reviewer sees behaviour and context together.
How is docs staleness measured?
In days, per page, against the API version the page documents — with a broken-example count beside it. The Orders docs lag v2.4 by 48 days because the create-order page still documents the v2.1 request body; the alert says exactly that.
What happens to deprecated APIs?
They stay visible with their traffic. The demo's deprecated MFA API still takes 624K requests a day, which is the argument for sunsetting being a traffic decision rather than a date decision.
Is Portal audited or certified?
No certification has been issued. What we can evidence about hosting, encryption and access is on the security page.
The portal is running. Check its promises.
Live build, demo data, no card. Then ask how many of your keys are unused but privileged.