Authentication
How to send a key, and which key opens which routes.
Loading documentation…
A board or page key goes in either header:
| Key | Where it's made | What it opens |
|---|---|---|
Board key sbk_… | A board's Settings → Developer | That board's /v1/ingest/* routes, within its scopes |
| Page key | A workspace page's (Leads, Deals…) Settings → Developer | That page's /v1/ingest/* routes, plus external_id retries |
A key only opens the routes its scopes cover; anything else answers 403. |
The other routes in the API reference are the ones the Specter app uses, and they
answer a signed-in session: Authorization: Bearer <access token> from POST /v1/auth/signin.
A board or page key is refused there.
| Scope | Allows |
|---|---|
read | GET /v1/ingest/board — columns, rows and the write guide |
rows:write | POST /v1/ingest/rows — add records. It never reads back what is already there |
Give each integration its own key with only the scopes it needs. A web form needs rows:write alone.
An unknown or revoked key answers 401:
No key at all — or something that isn't an sbk_… key — answers 401 with
a board API key is required.