csk_<prefix>.<secret> and belong to exactly one team. A key can never read or change another facility’s data.
Send your key
Use either header. They are equivalent.Create, rotate, and revoke keys
Team admins manage keys under Settings → Integrations → API in the dashboard. See Connect the API for the walkthrough.- Name keys after their purpose, such as Website inventory feed, so you know what breaks if you revoke one.
- Set an expiration for keys handed to contractors. Expired keys return
401 API key expired. - Revoke a key the moment it might have leaked. Revoked keys return
401 API key revokedimmediately. - Rotate by creating a new key, updating the integration, then revoking the old key.
Scopes
Each key carries a list of scopes. A request fails with403 Missing scope: <scope> when the key lacks the scope that endpoint needs. Each endpoint page lists its scope at the top of the description.
Write access is never implied by read access. A key that needs to create cars needs both read:cars (to look them up) and write:cars.
Some writes touch more than one resource. For example, logging a drop-off into a parking spot with
POST /cars/{id}/events also needs write:parking.API turned off
If a team admin turns the API integration off, every key on that team returns403 API is disabled for this team until it is turned back on. The keys themselves are kept.