Base URL
/v1.
Authentication
Send your credential as a bearer token on every request:
A project API key only works under
/v1/projects/{projectId}, for the project it
was issued for. Every other endpoint needs an account credential — all of
/v1/account, the /v1/projects collection, and invitations.
Pick the narrowest credential that reaches what you are testing. A project API
key is enough for most endpoints, and limits the damage if you leak it. Reach for
an account service key only when you need /v1/account or the project
collection.
Create an account service key through POST /v1/account/service-keys, using
an account access token or an existing account service key. Give the key a
name and an explicit expiry. Save the returned credential when you create it;
you cannot retrieve it again. To replace a lost key, revoke it and create another.
A handful of endpoints under /v1/auth are public and ignore the header.
Timestamps
Timestamps are RFC 3339 date-times in UTC with an upper-caseT and Z, for
example 2026-01-01T00:00:00Z. Responses always use this form; send timestamps
the same way.
Errors
Every error is an RFC 9457 problem document served asapplication/problem+json, carrying a stable type URI and
code you can match on:
type URI resolves to the page documenting that problem. See
Problems for the envelope and the full catalogue.
Browse the endpoints
The Endpoints group in the sidebar lists every operation, grouped by the area it belongs to. Each page documents the parameters, request body, and responses, and lets you send a request from the interactive playground. You can also read the schema directly at/openapi.json.
The WebSocket group below it covers
event delivery over WebSocket: how to connect, start a session,
receive events, and read the frame reference.