Getting started
Authentication
Authenticate every request with an API key in the Authorization header using the Bearer scheme. Create keys in Dashboard → API. Keys are shown once, stored as SHA-256 hashes, and can be rotated or revoked at any time.
Header
Send the key on every request. Keys start with rsk_live_.
Authorization: Bearer rsk_live_9f2c…Scopes
Read-only keys can call every GET endpoint. Read & write keys can also create, update and delete resources. Write keys act with Manager-level permissions in the workspace; billing and member management are never available through the API.
Key hygiene
Never embed keys in browser code or mobile apps. Store them in a secret manager, use one key per integration, set an expiry for temporary access and rotate keys if they may have been exposed.