Skip to content
OUTIS DOCS

Authentication

The v1 API authenticates with an API key sent as a bearer token. Generate keys on your organization’s keys page in the dashboard; a key names the organization every request lands in.

Authorization: Bearer <token>
outis_sk_<12 hex, the public id>_<43 base64url characters, the secret>

outis_sk_xxxxxxxxxxxx_NOT-A-REAL-KEY-THE-REAL-ONE-IS-LONGER

The head, the family marker plus the public id, is what a list view and a log line show. The secret is shown once, when the key is generated, and the server stores only a keyed hash of the token.

SCOPELETS A KEY
proposecreates requests
readreads a request's decision
executefinds, claims and reports an authorized request's sealed intent

A key can hold any mix of them. A service that asks holds propose and read; a worker that runs sealed intents holds read and execute. A key can’t authorize, stage, arm or commit; those take a person at a box.

A key that’s absent, malformed, unknown, revoked or wrong gets the same 401, with a body that names neither the key nor the reason. A live key that lacks the scope a route needs gets a 403 that says so.

Revoking a key takes effect on its next use.