Skip to main content
Send a bearer token or Veryfront API key with authenticated requests. Each endpoint lists its accepted credentials and required permissions.

Bearer tokens and API keys

Send either credential in the Authorization header:
request.http
For an API key, you can also use the X-API-Key header:
request.http
Use the API key endpoints to manage keys. Use the authentication endpoints for supported sign-in and token flows. Some endpoints require a signed-in user and reject API keys. Check the endpoint’s Authentication section before choosing a credential.

Resource permissions

Authentication identifies the caller. Resource permissions determine which projects, conversations, runs, and other resources the caller can use. A project-bound credential cannot access another project. Project access does not automatically grant access to every private conversation. Endpoints can also restrict actions by role or token scope. Manage access through account members, project members, and the relevant resource permissions.

Runtime credentials

Runtime integrations publish events and report execution outcomes with credentials bound to their permitted work. For example, a run event-writer token authorizes event publication for its bound run. Read the authentication requirements for the run endpoint before using a runtime credential. Access to a run alone does not authorize every runtime operation.

Anonymous access

Some catalogs and metadata endpoints allow anonymous requests. Public endpoints can still require authentication.

Other interfaces

GraphQL, MCP, and WebSocket use their own request or connection contracts. See GraphQL, MCP, and streaming for entry points and protocol references. Back to REST API reference