1. Documentation
  2. Get started
  3. Authentication
Open Specter
  • Introduction
  • Quickstart
  • Authentication
  • Errors
  • Rate limits
  • Best practices
  • Overview
  • Best practices
  • Create a key
  • Read and write
  • Overview
  • Best practices
  • Hosted page
  • Submit from your code
  • Drafts, files and corrections

Authentication

How to send a key, and which key opens which routes.

Loading documentation…

Quickstart< PreviousErrorsNext >

On this page

Kinds of keyThe rest of the APIScopes on a board keyA bad key

A board or page key goes in either header:

http
Authorization: Bearer <key>X-API-Key: <key>

Kinds of key

KeyWhere it's madeWhat it opens
Board key sbk_…A board's Settings → DeveloperThat board's /v1/ingest/* routes, within its scopes
Page keyA workspace page's (Leads, Deals…) Settings → DeveloperThat page's /v1/ingest/* routes, plus external_id retries
A key only opens the routes its scopes cover; anything else answers 403.

The rest of the API

The other routes in the API reference are the ones the Specter app uses, and they answer a signed-in session: Authorization: Bearer <access token> from POST /v1/auth/signin. A board or page key is refused there.

Scopes on a board key

ScopeAllows
readGET /v1/ingest/board — columns, rows and the write guide
rows:writePOST /v1/ingest/rows — add records. It never reads back what is already there

Give each integration its own key with only the scopes it needs. A web form needs rows:write alone.

A bad key

An unknown or revoked key answers 401:

json
{"error": {"message": "that key does not work here"}}

No key at all — or something that isn't an sbk_… key — answers 401 with a board API key is required.