Integration
Bearer, TTL, storing PATHLY_API_TOKEN — never exposing the key in Git.
OpenAPI contractIssue an API keyFree Solo account
Full document, no authentication, ready for your client generator.
Every authenticated request carries Authorization: Bearer $PATHLY_API_TOKEN. A key belongs to the organisation, not the person. Issue it under Settings → API keys (owner or admin). The secret is shown only at creation: the database keeps only a hash.
Every key has a TTL: 365 days by default, 730 at most. A missing, unknown, revoked or expired key gets the same 401: telling these cases apart would enable token enumeration.
Store the secret in a manager (GitHub Actions secrets, GitLab CI variables, Vault, Secret Manager). Never in a commit, ticket, application log or versioned .tf file.
# Shell local / CI
export PATHLY_API_TOKEN=sp_…
# Jamais : curl -H "Authorization: Bearer sp_xxx_en_clair"