Skip to main content
Use a Veryfront API key or supported bearer token to authenticate API requests. Authentication identifies the caller; resource permissions determine which operations that caller can perform. Create an API key and store it in your server environment or secret manager.

1. Send an authenticated request

GET /projects
request.sh
A successful response lists projects visible to that credential. Keep API keys in server-side code. Do not include them in a public application bundle or commit them to source control.

Choose the required credential

Most authenticated operations accept bearer credentials. Some require a user session, a project-scoped token, or a token issued for a particular run or runtime operation. Use the credential specified by the endpoint or tool; an API key does not grant access to every operation. Public discovery and documentation pages can be browsed without credentials. Browsing a tool or operation does not grant permission to execute it.

Verify the result

The caller must have access to the account, project, or other resource involved in the request. A resource ID or project reference selects the resource; it does not grant access. If a request fails, inspect its error response. Check the credential’s validity, the required credential type, and the caller’s resource permissions. See Identity and Access API for the relationship between accounts, memberships, and API keys.

Next