Skip to content

Authentication

Every API request must include a bearer token in the Authorization header:

Authorization: Bearer <token>

Tokens are issued at sign-in and managed from API Keys inside the application. Keep tokens secret; treat them like passwords.

  • 401 Unauthorized: missing, expired, or invalid token.
  • 403 Forbidden: valid token, but your role does not permit this action.
  • 429 Too Many Requests: rate limited. The response includes a Retry-After header telling you how long to wait.

Try this in the platform