Authorization header.
The header
- Format:
Bearer <token>. The space betweenBearerand the token is required. - Send the full token, including the
kbai_pk_prefix. - HTTPS is required. Plain HTTP requests are rejected in production.
The token decides the tenant
Authorization is the only header that determines which company and project your request touches. Both are resolved from the token server-side, on every request, and neither is overridable by the caller.
They are absent from responses too. Records come back without tenant identifiers, so a payload you log or forward carries nothing about which company produced it.
Snippets that pass
company in a header or a body come from Keebai’s internal service-to-service calls, which run on a private network and predate the public surface. They do not apply here — if you inherited one, drop the header and mint a token instead.GET /v1/me.
Examples
Authentication errors
All auth errors return the same generic status and message — we don’t tell you whether a token is “missing” vs “revoked” to avoid handing enumeration hints to attackers.Where to store your token
Secret managers
AWS Secrets Manager, GCP Secret Manager, HashiCorp Vault, 1Password, Doppler. The right answer for production.
GitHub Actions
Repository Settings → Secrets → Actions → New secret. Reference as
${{ secrets.KEEBAI_API_TOKEN }}.Local .env
Personal dev only. Make sure
.env is in .gitignore.Server env vars
On servers:
export KEEBAI_API_TOKEN=.... Never in source code.Automatic leak detection
Thekbai_pk_ prefix is registered with GitHub’s secret scanning. If a token ends up in a public GitHub repo, you’ll get an alert and we’ll auto-revoke it.
To enable secret scanning on your private org repos: GitHub → Settings → Code security → Secret scanning.