Authentication
Bearer tokens, key rotation and revocation
Draft reference · Examples use sample data.
Authorization header
Send a Bearer token with each request. Use a server-side integration so your key is not exposed to visitors.
HTTP header
Authorization: Bearer YOUR_API_KEYKey lifecycle
- Create: generate the first key from your workspace.
- Rotate: replace the key, then update your integration.
- Revoke: disable the key when it is no longer needed.
The workspace supports one active key. It does not implement a rotation grace period.
Authentication failures
401 · application/json
{
"demo": true,
"error": "INVALID_API_KEY",
"message": "Create or select an active demo key."
}Check the key before retrying. Manage your demo key →