Integration

Authentication and API keys

Bearer, TTL, storing PATHLY_API_TOKEN — never exposing the key in Git.

OpenAPI contractIssue an API keyFree Solo account

Full document, no authentication, ready for your client generator.

Authentication and keys

Every authenticated request carries Authorization: Bearer $PATHLY_API_TOKEN. A key belongs to the organisation, not the person. Issue it under Settings → API keys (owner or admin). The secret is shown only at creation: the database keeps only a hash.

Every key has a TTL: 365 days by default, 730 at most. A missing, unknown, revoked or expired key gets the same 401: telling these cases apart would enable token enumeration.

Store the secret in a manager (GitHub Actions secrets, GitLab CI variables, Vault, Secret Manager). Never in a commit, ticket, application log or versioned .tf file.

# Shell local / CI
export PATHLY_API_TOKEN=sp_…
# Jamais : curl -H "Authorization: Bearer sp_xxx_en_clair"