Authentication
Every request carries an API key as a bearer token:
Authorization: Bearer harmony_pk_...
A request without a key, or with an unknown or revoked key, gets 401. Browser sessions and cookies are not accepted on the Public API.
What a key can do
A key acts as the Harmony user who created it, in that user's Account. It sees the same contacts and workflows that user sees, and everything it creates belongs to that Account.
Keys have no scopes and do not expire. Treat each key like a password:
- Keep keys on your servers. Never put a key in a browser, a mobile app, or a public repository.
- Create one key per integration, with a name that says what uses it, so you can revoke one integration without breaking the others.
Revoking a key
Revoke a key in Settings > Developers. The next request that uses it gets 401. Settings also shows when each key was last used, which helps you find keys that are no longer needed.
If a key may have leaked, revoke it and create a new one.