/ Softwerk Gateway

Authentication

Every request to a protected endpoint must include a valid customer API key.

API key header

Send your key in the x-api-key header:

curl https://gateway.softwerk.se/api/agents \
  -H "x-api-key: YOUR_API_KEY"

Requests without a key receive 401 with {"detail": "Missing API Key"}.

Key validation

Keys are validated against stored hashes in Firestore. Invalid or revoked keys also return 401.

ResponseMeaning
Missing API KeyNo x-api-key header
Invalid API KeyKey not found
Revoked API KeyKey was revoked

Public endpoints

These paths do not require authentication:

  • /health — liveness check
  • /openapi.json — OpenAPI schema
  • /swagger — Swagger UI (legacy)
  • /redoc — ReDoc
  • /docs — documentation site

All /api/* routes require a valid API key.

Security

  • Store API keys in a secret manager, not in source code.
  • Rotate keys when team members leave or credentials are exposed.
  • Use separate keys per environment.