Skip to main content

Base URL

API key

Every request takes your API key as a bearer token. There are no other credentials and no per-request signing.
Your key identifies your organization and the environment it acts in. Keep it server-side; it is not safe to expose in a browser or mobile client. In the API reference playground, paste your key into the Authorization field once and every “Try it” call sends it for you.

Environments

You have two environments, and the key you call with is what says which one a request is in. You hold a key for each. A key belongs to one environment and reaches only that environment’s workflows, so keep the two apart in your config exactly as you keep any other pair of environment credentials apart.
  • GET /workflows lists your uat workflows on a uat key, and your production workflows on a production key. A workflow is in one environment and appears in one listing.
  • Naming a workflow from the other environment is refused with 403, in both directions.
  • Verifications are scoped the same way. A record created on one environment’s workflow is not readable, listable or countable with the other environment’s key.
Every workflow reports its own environment, so a record you are unsure about can be traced back to it:
Each environment’s workflows carry their own credits and their own live ceiling, because they are separate workflows. Testing never draws down what you bought for real work. See Credits and limits.

A run is identical in both

The same steps, the same documents, the same sources, the same cross-checks and the same verdicts. What differs is only what you treat a run as.
uat is not a sandbox and nothing in it is mocked. A uat verification really reads the documents you send and really confirms them with the bodies that issued them, so use documents you are entitled to use and do not put invented data in front of a live registry.

Looking after the key

Your key is the whole of your access to the API, so hold it as you would any other production credential: in your secret store, out of source control and out of your logs, and with as few people as need it. Tell us if it is ever exposed and we issue a new one and retire the old.

When auth fails

Each of these responds with { "detail": "<message>" }. See Errors for every status the API returns.