Send the tenant API key as x-api-key or as a Bearer token
The delivery-purge API authenticates with exactly one credential: your workspace's tenant API key. It is the same key generated when the workspace was created — deliberately different from the sat_ service-account tokens used by the public read API.
Sending it#
Either header works:
# header style
curl -H "X-Api-Key: $TENANT_API_KEY" ...
# bearer style
curl -H "Authorization: Bearer $TENANT_API_KEY" ...With no credential the API answers 401 Authentication is required.; with a value that is not the tenant key it answers 401 Invalid API key. A session JWT will not work — a dashboard login token supplied here never resolves to an API-key context, so browser sessions are rejected by design. The key resolves to a disabled-tenant-checked lookup and acts as ADMIN for your tenant, and two other surfaces explicitly require this same apiKey context: edge-probe ingestion and (with a stricter message) purge itself.
Keep it server-side#
The tenant API key is a workspace credential. Store it in your CI secret store or deploy tooling, never in front-end code. If you need scoped, expiring credentials for other integrations, use Create a token instead — but for purge, the tenant key is the only accepted key.

