Authentication
Every tenant API request must include your API key.
Send it in the x-api-key header, or as Authorization: Bearer <key>:
x-api-key: <tenant-api-key>
Invalid, revoked, or suspended keys return 401 Unauthorized. The error message is intentionally identical in each case.
Rate limiting
The API allows 300 requests per 60 seconds per client. Exceeding the limit returns 429 Too Many Requests.