API authentication
Send your API key as a bearer token on https://api.avaloi.com/v1 and quote the request ID when you need help.
The public API uses bearer tokens. Send your key on every request to https://api.avaloi.com/v1.
curl -s https://api.avaloi.com/v1/companies/me \
-H "Authorization: Bearer hk_live_YOUR_SECRET"
Keys
Keys start with hk_live_ in production or hk_test_ on preview and staging, plus 32 random bytes. Avaloi stores a SHA-256 hash and shows the secret once. Create a key in API keys. See Create an API key and API keys and scopes.
To check the key you hold, call GET /v1/api-keys/current. It validates the key you sent and returns its scopes.
Dashboard sessions
The dashboard authenticates with HttpOnly cookies, not an API key. Cookie auth is for the browser only. Scripts use a key.
Request IDs
Every response includes a request ID. Quote it in support tickets. The same ID appears in the activity log and in Avaloi's error and log tooling, so support can find your call.
Quick answers
I get 401 on every call. The key is missing, unknown, or revoked. Create a new key and copy the secret again. Revocation takes effect within 5 seconds.
I get 403 on one call.
The key lacks a scope. For example, invitations need users:write and GET /v1/companies/me needs sites:read.
Can I use my dashboard login in a script? No. Create an API key.
API
GET /v1/api-keys/currentGET /v1/companies/me
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.