Authentication
For Developers

Authentication

Every API request is signed with an API key. A key belongs to one project (workspace): every call runs in that project, so there is no workspace_id in the URL. Keys have no scopes: a key opens every API endpoint for its project.

1. Create a key

  1. Open Settings → API Keys. Only the project owner and admins can manage keys.
  2. Click Create key and give it a name (for example, “CRM bridge”).
  3. Copy the key. The full key is shown only once; after that the list shows only its prefix. Format: sk_…

2. Send the key

Pass the key in the Authorization header with the Bearer scheme:

Authorization: Bearer sk_xxxxxxxxxxxxxxxxxxxxxxxx

3. Try it

curl
curl https://api.support.forestsnet.com/api/v1/tickets \
  -H "Authorization: Bearer sk_xxxxxxxxxxxx"

When the key is rejected

  • The key is wrong, disabled or deleted, doesn’t start with sk_, or the project is suspended: 401 with the body {"detail": "Invalid or revoked API key."}.
  • No Authorization header at all: 401 as well, with the body {"detail": "Missing API key: send Authorization: Bearer sk_..."}.
  • Both come with a WWW-Authenticate: Bearer header.

Disabling and deleting keys

In the same section you can disable a key for a while or delete it. A disabled or deleted key stops working at once.

Security. Don’t put an API key in frontend code, mobile apps or public repositories: it opens all of the project’s data. Delete keys you no longer use. Rate limits are on the Limits & errors page.
Was this page helpful?