GET /health and GET /openapi.json needs an API key. Send the key in the Authorization header:
Getting a key
An administrator of your Synthetic account creates keys under Settings → API keys. The secret is shown once, when the key is created. Store it in a secrets manager, not in source control.What a key can do
- A key reads the data of one business, the one it was created for. Data belonging to anyone else is not found.
- A key can only read. The API has no routes that create or change data.
- A key holds a fixed set of claims. Today the only claim is reading payments,
payments:read, and every key has it.GET /meshows a key’s claims asauthorizationClaims. - A business can create up to ten active keys.
Revoking a key
An administrator revokes a key from the same Settings → API keys page. Revocation takes effect immediately, and every request with that key is refused from then on. A request with a missing, unknown or revoked key returns401. See Errors.