Developers
Authenticating public API requests
Public API routes (distinct from the session-authenticated dashboard API) accept a service-account token as a standard Authorization: Bearer <token> header. Each route declares the scope it requires; a token without that scope is rejected the same way an invalid one would be.
How it works
- GET /v1/public-api/domains (requires the "read" scope) lists your tenant's connected domains
Good to know
- Treat the token like any other production secret — anyone holding it can call every route within its granted scopes until it's revoked or expires

