team · Fornace Pi
Team identity, keys & budgets.
The Payme roster, Telegram bot gateway, monthly model budgets, and teammate relay API.

Platform components & access
| Component | Purpose & Authorization |
|---|---|
| @fornaceaibot | Team Telegram bot. Send /key to receive your personal Mantice gateway token. |
| Matchbox | Passkey credential broker at matchbox.fornace.app. Enrolls your Mac via Touch ID for scoped provider access (Meta, Vercel, Fal.ai) without raw keys. |
| Mantice Router | Unified model gateway at https://llm.fornace.net/v1. Enforces monthly spending caps per key. |
| DramaFoundry | Short drama studio at dramafoundry.fornace.net. Account auto-provisioned via your team key during setup. |
| Teammate Relay | Your agent can DM colleagues directly through the bot, authenticated by your key and signed with your name. |
| Pi Agent | Your local coding agent running inside cmux on Apple Silicon. |
System map & authorization flow

Payme roles & monthly budgets
| Payme Role | Monthly Spend Limit | Bot Capabilities |
|---|---|---|
| member | $200 / month | chat + /key |
| pm | $400 / month | chat + /key + /sync |
| admin | unlimited | + /broadcast, /budget, colleague onboarding |
Roles are synced from Payme. Admins: Francesco, Luca. Per-person overrides can be set by admins via /budget <name> <amount> in the bot or via the API below. A budget change re-mints the gateway key and DMs it.
Agent-to-teammate relay API
Your Pi agent can send messages to teammates via the Telegram gateway:
KEY=$(python3 -c "import json;print(json.load(open('$HOME/.pi/agent/auth.json'))['fornace']['key'])")
curl -s -X POST https://llm.fornace.net/auth/relay/telegram \
-H "Authorization: Bearer $KEY" -H "Content-Type: application/json" \
-d '{"to":"luca cisorio","text":"Pipeline test complete: all green"}'
Delivered as: From <Your Name> (via agent). Rate limit: 20 messages per hour. Recipient must have pressed START in the bot once.
Budget management API (admins only)
curl -s -X POST https://llm.fornace.net/auth/budget \
-H "Authorization: Bearer $ADMIN_KEY" -H "Content-Type: application/json" \
-d '{"to":"fabrizio","monthly_usd":800}'
Security & operations
| Key Refresh | Lost your token? Send /key to @fornaceaibot anytime to re-display your active token. |
| Daily Updates | Automated manifest verification runs daily at 05:51 UTC with automatic rollback on failed checks. |
| Network Security | No inbound ports exposed. All calls are outbound over HTTPS, authenticated via bearer tokens or passkeys. |
| Source Repos | Identity bridge: fornace-keys | Distribution: Fornace/pi-setup |