Skip to main content

Base URL

Every request goes to your workspace’s subdomain (acme in the examples):

Authentication

Create an API key under Settings > API keys, then send it as a bearer token in the Authorization header:
  • A key belongs to one workspace, and only works on that workspace’s subdomain.
  • A key can do only what its scopes allow, and its scopes never exceed the permissions of the member who created it.
  • A missing, invalid, expired, or revoked key gets a 401. A key without the permission an endpoint needs gets a 403.
  • API keys can’t create, rotate, or revoke API keys. Those endpoints need a signed-in session.

Responses

Every JSON response has the same envelope. A single resource comes back under result:
A list comes back under results, with cursor pagination. Pass nextCursor back as cursor to get the next page:
A failed request keeps its HTTP status, returns null for result, and lists what went wrong in errors:
errorCode is stable, so branch on it rather than on errorMessage.

Concurrent updates

Resources that more than one person can edit return an ETag header. To update one, send that value back in If-Match. A request without it gets a 428, and a request made against an older version gets a 412: fetch the resource again and retry.

Manage API keys

Create, rotate, and revoke keys.

Roles and permissions

The scopes a key can hold.