---
tags: help, projects
order: 10
description: creating one, members, roles and permissions
---
# Help: projects

A project is your own space in d2: its own address, wiki, domain, objects and files, and its own members. Everything in it stays in it; nothing is shared with other projects except what d2 itself shares (this help, the AI skills d2-maker, d2-agents and d2-guardian).

## Create one

1. **Sign up or log in** on [aiheroapps.com](https://aiheroapps.com). You land on your account home, which lists your projects.
2. **Name it** under **New project**. A name is lower-case letters, digits and dashes, starting and ending with a letter or digit; it becomes the address, `<name>.aiheroapps.com`. d2 checks that it's free. Names starting with `d2` are reserved.
   While d2 is a prototype, new projects are named **`demo-`** and then your name: type `garden` and you get `demo-garden`, at `demo-garden.aiheroapps.com`. The form shows the full name and address as you type, and the rules above (and *is it free?*) are checked on the full name. Projects that already exist keep the names they have.
3. **Pick its level**, one per kind of user. It sets the menu and the home page you start with; change it later in the project's settings (`Settings:PROJECT`).
   - **Hero**: your own app, no code. Home, wiki, data and files.
   - **Creator**: you model and build. Adds the domain and the model graph.
   - **Pro**: the full kit. Adds the fiddle, flows and the API.
4. **You own it**, as its first admin. It opens on its home page; its landing page is what visitors see.

New projects need a new web address each, and d2 can make only so many a week (about 40). If that's used up, the create page says when the next one frees up.

## Who can do what

Everyone in a project has a **role**. Roles nest: each can do everything the one below it can.

- **public**: anyone, logged in or not. Sees the landing page, and what's marked public.
- **member**: reads the project, writes topics and objects, uploads files, makes AI tokens for themselves.
- **mod**: also edits the landing page and special pages, and replaces or deletes anyone's files.
- **admin**: also sees **This project** on the **Settings** page (in the user menu, in the admin colour): **Members** (who's in, their roles, requests, invites), **Project** (versions, level, who can join, who can read and change it), **Quotas** (what the plan allows and what's used) and **Init**. The owner is an admin.
- **the Architect** is d2's own administrator: admin in every project.

### What may be read, and by whom

Everything readable carries two levels, **view** (who may read it) and **edit** (who may change it), each one of `public`, `member`, `mod` or `admin`. One question is asked of the same four places, the most specific first:

1. the topic's own frontmatter (`view: public`, `edit: mod`): a mod's to add or change;
2. its category, or an object's class (`@view`, `@edit`): `Settings:` topics are the mods', `Spec:` topics are changed by mods, your `Memory:` and `Skill:` topics are yours (`edit: owner` means you, plus the mods), and the logs are only ever added to;
3. the project's own **view** and **edit**, on **Admin → Project**: an admin's to change, and what makes a project private;
4. and if nothing says otherwise, `member` and `member`.

A page you may not read says so at its own address, with **Log in** if you aren't logged in, and names the level it wants if you are; it never appears in a list, a search, the tags or the history either, and a link to it reads as plain text. The landing page is always public, since it's where people log in. An AI token can only ever be narrowed further, by `ai-access` on a topic and by the level the token was made with.

## Let people in

On **Admin → Project** (admins), choose **who can join**:

- **request** (the default): people press *Request to join* on the landing page; you approve or deny on **Admin → Members**, and they're told.
- **open**: anyone who's logged in can press *Join* and becomes a member.
- **invite**: only people you add get in. To keep visitors out of the project as well, set **view** to `member` on **Admin → Project** (that, not the join setting, is what makes a project private).

**Invite someone** by email on **Admin → Members**, with the role they'll have. The invite is a link, good for 7 days, and works whatever the join setting; opening it (logged in as that email) makes them a member. A new invite to the same person replaces the old one.

**Change a role** or **remove** someone on **Admin → Members**. You can't remove the last admin.

## Once you're in

- **Single sign-on:** logged in on one project and a member of another, *Log in* there needs no password.
- **Your AI** gets its own token: **Settings → AI permissions** (the **AI tokens** tab), at most your own level (or read only), expiring in 30 days, 90 days, a year, or never. Tick *drafts* to have its topic changes wait for you on your **Drafts** page. Revoke it on the same page. See [Connect your AI](/help#connect-your-ai).
- **Scope:** a token is for **this project** (the default), or, on the Yearly and Monthly plans, for **all my projects**: every project you own, new ones included, never one where you're only a member or an admin. It's one agent everywhere (one vault key, the same name in every project's history); revoking it anywhere revokes it everywhere. Used where it doesn't reach, it's refused with `E_TOKEN_SCOPE`, saying where it works. On the free plan an all-projects token is paused everywhere except the project it was made on.
- **Plans and quotas:** a project follows its owner's plan: **Free**, **Yearly** ($20 a year) or **Monthly** ($20 a month). The plan sets its limits: files and their size, objects and their size, members, how long a flow may run. **Admin → Quotas** shows each limit and what's used, and says where it comes from — the plan, or a limit set for your project alone, with the note behind it; the table for every plan is `Settings:Quotas` in d2. On free: 20 files and 5 MB, 1000 objects, 3 members, 5 s a flow. **Your plan** (user menu → **Plan**, `/account/plan`) shows yours and moves you between them: *Upgrade* goes to PayPal's checkout, where you approve a payment that renews each period until you cancel; the plan changes when PayPal confirms it. *Switch* to a bigger plan starts at once, to a smaller one at the end of the period paid for; *Cancel plan* keeps it to the end of that period, and you can cancel in PayPal too. A failed payment warns you and gives you 7 days to fix it in PayPal before the plan drops to Free. Only you change your plan: never your AI. At 70% of any quota a project's admins get a warning, at 85% an alert, once each per period; when a quota fills up the owner, the admins and d2's administrators get an alert (`N_QUOTA_FULL`), once per quota per period — with the write that fills it, which is kept, so the news comes before anything is refused; writes past it are then refused. A limit on one thing at a time — how big one object or one file may be, how much one batch may write — just refuses that call: it doesn't mean the project is full, and nobody is alerted. Payments run in PayPal's test mode (sandbox) for now.
- **The init page:** a project sets itself up in rules on its init page, `Settings:Init` (**Admin → Init**): what it needs when it starts, its crons, and how it reacts to its data. See [[Help:Init]].
- **Versions:** an admin releases a project version from **Admin → Project** (`1.2.0`); it rolls the project log and the AI log over.
- **Leaving:** delete your account from your preferences (`/prefs`). Projects you own keep their other members.

## For AIs and scripts

The same things through the API (every API route is on the [API page](/api)):

- `GET /api/v2/me`: who you are here, and your role.
- `GET /api/v2/projects/available?name=…`: is a name free.
- Writes need a member's session or a token: `Authorization: Bearer d2t_…`.
