Cloud & accounts

When you finish, you have a Sorb™ account with an organization, and you know what a publishable key and a secret key each let a caller do. You need nothing to configure — your first sign-in creates your first org automatically.

Get access

Sorb is free during the beta — no card required. Beta access is by request — request access. Once invited, you sign in at app.sorbcloud.com.

The first time you sign in with your invite, Sorb creates your organization and a default project for you automatically — there's nothing to configure before you can connect the plugin or push a preview.

The beta is as-is. It's not generally available yet — expect rough edges and active iteration. During the beta the hosted service stores org/project metadata and short-lived preview payloads. See the Privacy notice and Beta Terms.

Connect the plugin

Sign-in is the one path the plugin promotes: click Sign in to connect, and the plugin pairs itself with your account and org automatically — no server, URL, or key to type in. See Connect flows for the full walkthrough, including the fallbacks (an org key, a developer's invite, or a fully local bridge) that live under the plugin's Advanced setup.

Orgs, members & roles

Every project belongs to an organization. A member's role decides what they can do:

RoleCan
OwnerEverything, including billing. Every org has at least one; the last owner can't be demoted.
AdminInvite/remove members, configure org settings, connect GitHub, approve merges (open PRs, tokenize). Everything but billing.
EditorPropose changes and approve merges — day-to-day token work.
ViewerRead-only.

An owner or admin invites a teammate from the dashboard; the invite is a redeemable code, distinct from the plugin's own "handshake" invite (that one carries a connection, not org membership — see Connect flows). Accepting an invite joins you to the org at the role it was created with.

Projects & keys

A project is the unit an app connects to — its tokens, its keys, and (once connected) its GitHub repo all live under one project. Every project can issue two kinds of API key:

KeyPrefixMeant forScope
Publishablesorb_pk_…Embedding in a client — the plugin, the React SDK, a public demo.Read-scoped for most of the REST API; the hosted bridge additionally accepts it for pushing/updating a preview (previews are ephemeral, so this is a deliberate exception).
Secret(shown once at issuance, never redisplayed)A server, CI job, or the Sorb MCP server.Read-write — required for everything that commits, publishes, or opens a pull request.

Issue, rotate, and revoke keys from a project's Keys page in the dashboard:

  • Issuing a key returns its raw value exactly once — copy it before navigating away; Sorb never stores or re-derives it.
  • Rotating a key revokes it and issues a fresh one of the same type and project in one step, so you swap a leaked or expiring key without reconfiguring which project it's for.
  • Revoking a key is immediate and idempotent — revoking an already-revoked key is a no-op, not an error.

A key only ever acts on the one project it was issued for, even for a caller in the same org with access to other projects — this is enforced server-side, not just a dashboard convention.

What's free vs. hosted

Local loopHosted account
CostFree, no accountFree during the beta
Bridgesorb dev on your machineCloud bridge, no install
Team connectA developer's handshake inviteSign in, or an org key
DataStays on your machineOrg/project metadata + short-lived previews

Pricing

During the beta, Sorb is free — no card required. Pricing lands at general availability. See the pricing overview.

Next

Works with Figma. Not affiliated with, or endorsed by, Figma. Figma is a trademark of Figma, Inc.