Evidence-backed facts
- Weaviate documents API-key and OpenID Connect authentication and distinguishes identity verification from authorization permissions. informative
- An authenticated principal can be assigned read-only authorization, and an application must not infer broader object, collection, or administrative access. informative
- Creating or changing data and schema requires write authority distinct from authentication and read-only access. informative
- Anonymous access is strongly discouraged outside development or evaluation; documentation creates no instance, identity provider, key, role, dataset, or successful search. informative