Skip to main content
All /api/v1/... requests require a CollabOS API key.
Workspace keys use the same header:

Alternative: X-API-Key

If both headers are present, CollabOS uses the Authorization Bearer value.

Personal and workspace keys

A personal key cannot be used on a workspace-only endpoint, and a workspace key cannot be used on a personal-only endpoint.

Example request

Management authentication

Routes under /api/developer/... are different. They use the authenticated CollabOS dashboard/session JWT, not a developer API key. These routes create and revoke API keys and manage webhook endpoints.
Never expose a CollabOS API key in browser JavaScript, public source code, logs, or client-side applications. Keep it on a trusted server.