Skip to content
Getting started

Authentication

Authenticate every request with an API key in the Authorization header using the Bearer scheme. Create keys in Dashboard → API. Keys are shown once, stored as SHA-256 hashes, and can be rotated or revoked at any time.

Header

Send the key on every request. Keys start with rsk_live_.

Authorization: Bearer rsk_live_9f2c…

Scopes

Read-only keys can call every GET endpoint. Read & write keys can also create, update and delete resources. Write keys act with Manager-level permissions in the workspace; billing and member management are never available through the API.

Key hygiene

Never embed keys in browser code or mobile apps. Store them in a secret manager, use one key per integration, set an expiry for temporary access and rotate keys if they may have been exposed.