Base URL
Every request goes to your workspace’s subdomain (acme in the examples):
Authentication
Create an API key under Settings > API keys, then send it as a bearer token in theAuthorization header:
- A key belongs to one workspace, and only works on that workspace’s subdomain.
- A key can do only what its scopes allow, and its scopes never exceed the permissions of the member who created it.
- A missing, invalid, expired, or revoked key gets a
401. A key without the permission an endpoint needs gets a403. - API keys can’t create, rotate, or revoke API keys. Those endpoints need a signed-in session.
Responses
Every JSON response has the same envelope. A single resource comes back underresult:
results, with cursor pagination. Pass nextCursor back as cursor to get the next page:
null for result, and lists what went wrong in errors:
errorCode is stable, so branch on it rather than on errorMessage.
Concurrent updates
Resources that more than one person can edit return anETag header. To update one, send that value back in If-Match. A request without it gets a 428, and a request made against an older version gets a 412: fetch the resource again and retry.
Manage API keys
Create, rotate, and revoke keys.
Roles and permissions
The scopes a key can hold.