Skip to content
Pathwize API

Authentication

Authenticate every request with an API key in the Authorization header.

API keys are created in the dashboard under Developers. A key grants full access to every task in your workspace. Send it as a bearer token:

curl https://www.gopathwize.com/api/v1/tasks \
  -H "Authorization: Bearer pw_live_..."

Managing keys

  • Keys start with pw_live_. The full key is shown once at creation; afterwards only its prefix.
  • You can hold up to 10 active keys, for example one per environment or pipeline.
  • Revoking a key takes effect immediately. Create the replacement first, switch, then revoke.
  • Keys are hashed at rest. If you lose one, revoke it and create a new one.

Security

Never ship a key in client-side code or commit it to a repository. Keep it in an environment variable on your server. All requests must use HTTPS; plain HTTP is refused.

Authentication errors

A missing, malformed or revoked key returns 401 with "type": "authentication_error". Accessing a task from another workspace returns 404, so task IDs cannot be probed.