Every API request carries a bearer token:
Authorization: Bearer mr_live_…
Short answer
No header, no access. The key identifies both the caller and the workspace, so there is no separate workspace ID to pass.
Scopes
A key is created with an explicit set of scopes and can only do what those scopes allow:
campaigns:read,campaigns:writecontacts:read,contacts:writesequences:read,sequences:writemailboxes:readanalytics:readreplies:readwebhooks:read,webhooks:write
Two blanket scopes also exist: read (read access to everything the API exposes) and write (read and write access to everything).
Checking what a key can do
GET /me returns the key's workspace, its scopes and its per-minute rate limit. Call it first whenever an integration misbehaves.
Error responses
401 unauthorized/invalid_api_key— missing or malformed key401 api_key_revoked— the key was revoked in Settings → API Keys401 api_key_expired— the key passed its expiry date403 insufficient_scope— the key is valid but lacks the scope for that endpoint
Important notes
Treat a key like a password. Store it in an environment variable or a secret manager, never in front-end code or a public repository.
Was this article helpful?
Frequently asked questions
- Can one key access several workspaces?
- No. A key resolves to exactly one workspace. Create a separate key per workspace.
- Can I widen a key's scopes later?
- Create a new key with the scopes you need and revoke the old one. Scopes are fixed at creation so an existing integration's blast radius cannot silently grow.
