Access tokens
Every request to/api/v1 needs an access token in the X-API-KEY header:
- Generate tokens in your dashboard under API keys, or with the API keys endpoints. A token is shown once: the engine only stores its SHA-256 hash.
- Revoke a token in the same place. It stops working at once.
- Give each app or environment its own token, so you can revoke one without affecting the others.
- Tokens go in the header only. A token in the query string is ignored.
401 Unauthorized
DSN
Your DSN is your workspace’s API address, shown on your dashboard, for examplehttps://mail-api.example.com. All API paths start with /api/v1:
API keys
You can also manage access tokens through the API. Each key has apk_… id.
Create a key
string
required
Your name for the key, up to 100 characters.
Response
key is the access token. It’s in this response only, so store it safely.