Authentication Overview
The Extend API uses Bearer token authentication for all API requests. You’ll need to use your API token when instantiating the client if you’re using the SDK or in the Authorization header of each request if you’re using the API directly.
Obtaining an API Token
- Navigate to the Extend Developer Settings
- Create a new API key or copy an existing one
Important: Keep your API tokens secure and never share them publicly. Rotate them regularly and immediately if they’re ever compromised.
API Key Scopes
API keys have a scope of either organization or workspace:
- Workspace keys — Scoped to a single workspace and work for requests to that workspace.
- Organization keys — These keys work across any workspace in the org. Must be used with the
X-Extend-Workspace-Idheader to specify the workspace. Only org admins can create keys with organization scope.
Example Usage
Error Handling
If authentication fails, you’ll receive a 401 Unauthorized response. Common causes include:
- Missing the Authorization header
- Invalid token format
- Expired or revoked token
- Insufficient permissions for the requested resource

