Skip to content

Using the API

Authentication

API keys, where they go, and what each one can reach.

Every request carries a project API key in the Authorization header, after the word ApiKey:

Authorization: ApiKey ak_...

Call the API from your server. A key acts as its project: never put it in a browser, a mobile app or a public repository.

Create a key

  1. Open the project's API keys

    In the app, open the project and choose API keys.

  2. Create the key

    Name it after where it runs ("Invoice importer"), and choose its scopes. A key can also expire and accept requests only from the IP addresses you list.

  3. Copy it once

    The full key is shown only when it's created; afterwards the app shows its first characters. Store it in your secrets manager or an environment variable.

What a key can reach

  • One project. A key works only on paths of its own project: calling /v1/projects/{project_id}/... with another project's id returns 403 forbidden.
  • Its scopes. Scopes grant reading or writing one kind of resource:
ScopeAllows
tables:read, tables:write, tables:deleteReading, creating and editing, deleting tables
columns:writeAdding, editing and reordering columns
rows:read, rows:write, rows:deleteReading, creating and editing, deleting rows
extract:writeRunning extractions and schema suggestions
export:readExports and downloads
webhooks:manageCreating and managing webhooks

Each plan allows a number of keys per project: 2 on Free, 10 on Pro, 50 on Scale and 200 on Enterprise.

Rotate a key

Create the new key, deploy it, then revoke the old one in the app. Both work in between, so nothing fails while you switch.

Errors

StatusCodeMeaning
401unauthorizedThe header is missing or the key is wrong, expired or revoked
403forbiddenThe key is for another project, lacks the scope, or the request comes from an IP the key doesn't allow
403org_suspendedThe organization's payment failed; update it to restore access
429too_many_requestsSlow down: see Rate limits
Note

Authorization: Bearer ... is for the Anyrow app's own sessions and OAuth clients, not API keys: a key sent as Bearer is rejected.