Skip to main content
The MeetingKit API authenticates with a personal API key sent in the Authorization header. Get your key from your API settings page. Include the key in the Authorization header of every request:

Accepted header formats

The bare key is the canonical form. If your HTTP client or a generated SDK insists on an auth scheme, these all authenticate too, and the scheme is case-insensitive:

Keys and workspaces

Your API key is personal: requests act as your user, and you can access any workspace you’re a member of. Most endpoints take a workspace_id parameter to select which one — list yours with GET /workspaces.
Keep your API key secret. Don’t commit it to version control or expose it in client-side code. If a key leaks, regenerate it from your API settings page.

When authentication fails

Every failure returns 401 Unauthorized with an error whose code tells you which kind it is: A request with no valid key has no pin: send the Happyscribe-Version header to get this body. A request that names no workspace when the endpoint needs one is a 400, not a 401 — see Errors.

Versioning

Your key is pinned to the API version that was current the first time it was used, and every response says which version served it. See Versioning for the Happyscribe-Version header and how upgrades work.