Cloud & accounts
When you finish, you have a Sorb™ account with an organization, and you know what a publishable key and a secret key each let a caller do. You need nothing to configure — your first sign-in creates your first org automatically.
Get access
Sorb is free during the beta — no card required. Beta access is by request — request access. Once invited, you sign in at app.sorbcloud.com.
The first time you sign in with your invite, Sorb creates your organization and a default project for you automatically — there's nothing to configure before you can connect the plugin or push a preview.
The beta is as-is. It's not generally available yet — expect rough edges and active iteration. During the beta the hosted service stores org/project metadata and short-lived preview payloads. See the Privacy notice and Beta Terms.
Connect the plugin
Sign-in is the one path the plugin promotes: click Sign in to connect, and the plugin pairs itself with your account and org automatically — no server, URL, or key to type in. See Connect flows for the full walkthrough, including the fallbacks (an org key, a developer's invite, or a fully local bridge) that live under the plugin's Advanced setup.
Orgs, members & roles
Every project belongs to an organization. A member's role decides what they can do:
| Role | Can |
|---|---|
| Owner | Everything, including billing. Every org has at least one; the last owner can't be demoted. |
| Admin | Invite/remove members, configure org settings, connect GitHub, approve merges (open PRs, tokenize). Everything but billing. |
| Editor | Propose changes and approve merges — day-to-day token work. |
| Viewer | Read-only. |
An owner or admin invites a teammate from the dashboard; the invite is a redeemable code, distinct from the plugin's own "handshake" invite (that one carries a connection, not org membership — see Connect flows). Accepting an invite joins you to the org at the role it was created with.
Projects & keys
A project is the unit an app connects to — its tokens, its keys, and (once connected) its GitHub repo all live under one project. Every project can issue two kinds of API key:
| Key | Prefix | Meant for | Scope |
|---|---|---|---|
| Publishable | sorb_pk_… | Embedding in a client — the plugin, the React SDK, a public demo. | Read-scoped for most of the REST API; the hosted bridge additionally accepts it for pushing/updating a preview (previews are ephemeral, so this is a deliberate exception). |
| Secret | (shown once at issuance, never redisplayed) | A server, CI job, or the Sorb MCP server. | Read-write — required for everything that commits, publishes, or opens a pull request. |
Issue, rotate, and revoke keys from a project's Keys page in the dashboard:
- Issuing a key returns its raw value exactly once — copy it before navigating away; Sorb never stores or re-derives it.
- Rotating a key revokes it and issues a fresh one of the same type and project in one step, so you swap a leaked or expiring key without reconfiguring which project it's for.
- Revoking a key is immediate and idempotent — revoking an already-revoked key is a no-op, not an error.
A key only ever acts on the one project it was issued for, even for a caller in the same org with access to other projects — this is enforced server-side, not just a dashboard convention.
What's free vs. hosted
| Local loop | Hosted account | |
|---|---|---|
| Cost | Free, no account | Free during the beta |
| Bridge | sorb dev on your machine | Cloud bridge, no install |
| Team connect | A developer's handshake invite | Sign in, or an org key |
| Data | Stays on your machine | Org/project metadata + short-lived previews |
Pricing
During the beta, Sorb is free — no card required. Pricing lands at general availability. See the pricing overview.
Next
- Connect flows — sign in, plus every fallback.
- Cloud REST API — the key/org routes, in full.
- Troubleshooting — if a connection or preview fails.
Works with Figma. Not affiliated with, or endorsed by, Figma. Figma is a trademark of Figma, Inc.