Using the API
Authentication
API keys, where they go, and what each one can reach.
Every request carries a project API key in the Authorization header, after the word ApiKey:
Authorization: ApiKey ak_...Call the API from your server. A key acts as its project: never put it in a browser, a mobile app or a public repository.
Create a keyLink to section
Open the project's API keysLink to section
In the app, open the project and choose API keys.
Create the keyLink to section
Name it after where it runs ("Invoice importer"), and choose its scopes. A key can also expire and accept requests only from the IP addresses you list.
Copy it onceLink to section
The full key is shown only when it's created; afterwards the app shows its first characters. Store it in your secrets manager or an environment variable.
What a key can reachLink to section
- One project. A key works only on paths of its own project: calling
/v1/projects/{project_id}/...with another project's id returns403 forbidden. - Its scopes. Scopes grant reading or writing one kind of resource:
| Scope | Allows |
|---|---|
tables:read, tables:write, tables:delete | Reading, creating and editing, deleting tables |
columns:write | Adding, editing and reordering columns |
rows:read, rows:write, rows:delete | Reading, creating and editing, deleting rows |
extract:write | Running extractions and schema suggestions |
export:read | Exports and downloads |
webhooks:manage | Creating and managing webhooks |
Each plan allows a number of keys per project: 2 on Free, 10 on Pro, 50 on Scale and 200 on Enterprise.
Rotate a keyLink to section
Create the new key, deploy it, then revoke the old one in the app. Both work in between, so nothing fails while you switch.
ErrorsLink to section
| Status | Code | Meaning |
|---|---|---|
| 401 | unauthorized | The header is missing or the key is wrong, expired or revoked |
| 403 | forbidden | The key is for another project, lacks the scope, or the request comes from an IP the key doesn't allow |
| 403 | org_suspended | The organization's payment failed; update it to restore access |
| 429 | too_many_requests | Slow down: see Rate limits |
Authorization: Bearer ... is for the Anyrow app's own sessions and OAuth clients, not API
keys: a key sent as Bearer is rejected.