Skip to main content

Bearer Token Authentication

All API requests require authentication using a Bearer token in the Authorization header.

Making Authenticated Requests

Include your API key in every request:

Key Scoping

Each API key is scoped to a single knowledge base. This means:
  • You can only query the knowledge base the key was issued for
  • Attempting to query a different knowledge base returns 403 Forbidden
  • If you have access to multiple knowledge bases, you’ll have separate keys for each

Authentication Errors

Example error response:

Security Best Practices

Never expose your API key in client-side code, public repositories, or logs.
1

Use Environment Variables

Store keys in environment variables:
2

Server-Side Only

Make API calls from your backend, never from browsers or mobile apps.
3

Rotate if Compromised

If a key is exposed, revoke it immediately from your Dashboard and generate a new one.

Next Steps

Query Endpoint

Start querying knowledge bases

Rate Limits

Understand usage limits