← Blog

design

Never trust a header to tell you who is spending

End-user attribution has one correct shape, and a header is not it.

11 August 2026 · By Marcus Bell, Platform · 5 mins

The tempting design is a header: `X-End-User: ada@acme.com`, set by the caller, read by the gateway, written to the usage record. It is one line of code and it is wrong.

A header is an assertion. Anything holding the key can set it to anything, which means your usage records are a record of what callers claimed rather than what happened.

Attribution belongs on the credential. One key per end user, minted by the tenant, bound to that person and their wallet at the moment it is created. The caller does not get to say who they are, because the key already did.

It costs a mint per customer. In exchange, every row in the ledger is something you can stand behind.

Subscribe to our newsletter

Enter your contact details to get the latest news and trends to help boost your product.

Seams collects and processes your personal data to deliver the newsletter you requested. Learn more about how we manage your data and your rights.

Ready? Let's go.

Whether you want to examine the specific needs of your product, or go over the benefits of Seams, we are here for you.