Overview
Authentication & API keys
Every request is authenticated with a personal API key sent as a Bearer token.
Sending the key#
Add the Authorization header to every request:
GET /open/v1/me HTTP/1.1
Host: api.linework.app
Authorization: Bearer lwk_aBcD1234...
All requests must use HTTPS. Keys in query strings or in the body are not accepted.
About API keys#
| Property | Details |
|---|---|
| Format | lwk_ + 40 letters and digits |
| Owner | The Linework account that created it. Every action is made as that account. |
| Permissions | The scopes chosen when the key was created. They cannot be changed later: create a new key instead. |
| Visibility | Shown only once, at creation. Linework stores only a hash and cannot show it again. |
| Limit | Up to 5 active keys per account. |
| Expiry | Keys do not expire. They stop working when you revoke them or when developer access is revoked. |
Managing keys#
Everything happens in web.linework.app → Settings → Developers:
- Create a key, give it a name and pick the scopes.
- Revoke a key: it stops working immediately, with no way back. Revoked keys do not count toward the 5-key limit.
- See when each key was last used, to spot keys you no longer need.
Rotating a key#
- Create a new key with the same scopes.
- Deploy it to your integration.
- Check that requests work, then revoke the old key.
Keeping keys safe#
- Keep keys on your server. Never put a key in a mobile app, a browser page, a public repository or a support message.
- Give each key only the scopes it needs, and use one key per integration.
- If a key leaks, revoke it at once and create a new one. Linework staff will never ask for your key.
Authentication errors#
| Status | Code | Meaning |
|---|---|---|
| 401 | INVALID_API_KEY | The header is missing, the key is wrong, or it was revoked. |
| 403 | INSUFFICIENT_SCOPE | The key is valid but does not have the scope this endpoint needs. |
| 403 | DEVELOPER_ACCESS_REVOKED | Developer access for the account was suspended or revoked. All its keys stop working. |
| 403 | PROFILE_INCOMPLETE | Write endpoints need an account with a profile photo and a cover. |
See all codes in Errors.