Skip to main content
Authenticated API requests use a bearer access token:
Access and refresh tokens are issued by the authentication flow. Access tokens are short-lived; use the refresh flow rather than embedding long-lived credentials in a browser bundle. Public exceptions include health and selected account/bootstrap endpoints as defined by the running public OpenAPI contract. The public OpenAPI document is the authority for exact paths, schemas, and status codes.