Skip to content

API authentication

Send your API key as a bearer token on https://api.avaloi.com/v1 and quote the request ID when you need help.

The public API uses bearer tokens. Send your key on every request to https://api.avaloi.com/v1.

curl -s https://api.avaloi.com/v1/companies/me \
  -H "Authorization: Bearer hk_live_YOUR_SECRET"

Keys

Keys start with hk_live_ in production or hk_test_ on preview and staging, plus 32 random bytes. Avaloi stores a SHA-256 hash and shows the secret once. Create a key in API keys. See Create an API key and API keys and scopes.

To check the key you hold, call GET /v1/api-keys/current. It validates the key you sent and returns its scopes.

Dashboard sessions

The dashboard authenticates with HttpOnly cookies, not an API key. Cookie auth is for the browser only. Scripts use a key.

Request IDs

Every response includes a request ID. Quote it in support tickets. The same ID appears in the activity log and in Avaloi's error and log tooling, so support can find your call.

Quick answers

I get 401 on every call. The key is missing, unknown, or revoked. Create a new key and copy the secret again. Revocation takes effect within 5 seconds.

I get 403 on one call. The key lacks a scope. For example, invitations need users:write and GET /v1/companies/me needs sites:read.

Can I use my dashboard login in a script? No. Create an API key.

API

  • GET /v1/api-keys/current
  • GET /v1/companies/me

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.