Authentication
Every request to a protected endpoint must include a valid customer API key.
API key header
Send your key in the x-api-key header:
curl https://gateway.softwerk.se/api/agents \
-H "x-api-key: YOUR_API_KEY"
Requests without a key receive 401 with {"detail": "Missing API Key"}.
Key validation
Keys are validated against stored hashes in Firestore. Invalid or revoked keys also return 401.
| Response | Meaning |
|---|---|
Missing API Key | No x-api-key header |
Invalid API Key | Key not found |
Revoked API Key | Key was revoked |
Public endpoints
These paths do not require authentication:
/health— liveness check/openapi.json— OpenAPI schema/swagger— Swagger UI (legacy)/redoc— ReDoc/docs— documentation site
All /api/* routes require a valid API key.
Security
- Store API keys in a secret manager, not in source code.
- Rotate keys when team members leave or credentials are exposed.
- Use separate keys per environment.