Base URL
API key
Every request takes your API key as a bearer token. There are no other credentials and no per-request signing.Environments
You have two environments, and the key you call with is what says which one a request is in.
You hold a key for each. A key belongs to one environment and reaches only that environment’s
workflows, so keep the two apart in your config exactly as you keep any other pair of environment
credentials apart.
GET /workflowslists youruatworkflows on auatkey, and your production workflows on a production key. A workflow is in one environment and appears in one listing.- Naming a workflow from the other environment is refused with
403, in both directions. - Verifications are scoped the same way. A record created on one environment’s workflow is not readable, listable or countable with the other environment’s key.
A run is identical in both
The same steps, the same documents, the same sources, the same cross-checks and the same verdicts. What differs is only what you treat a run as.Looking after the key
Your key is the whole of your access to the API, so hold it as you would any other production credential: in your secret store, out of source control and out of your logs, and with as few people as need it. Tell us if it is ever exposed and we issue a new one and retire the old.When auth fails
Each of these responds with
{ "detail": "<message>" }. See Errors for every
status the API returns.