Skip to main content
A valid token authenticates a caller. Each endpoint separately checks whether that caller can perform the requested action on the resource. Use Find endpoints to filter the API by your token type and permissions.

Public API keys

Exchange a public API key’s client ID and secret at Create token, then send the returned access token in the Authorization: Bearer ... header.
  • Organization-scoped keys can exercise their granted public API permissions across the organization.
  • Team-scoped keys have an allowed_team_ids restriction. Every team checked by the request must be on that allowlist. Organization-level and user-level checks fail even when the URL names an allowed team.
  • Permission bundles limit the actions a key can perform. Select the exact bundles granted to your key in the endpoint filter. A full-access key still has only the public API key permissions; it does not become a user token.
The token exchange follows OAuth2’s client-credentials flow, but the resulting token still represents an API key. In the endpoint filter, select API key, not OAuth.

User OAuth tokens

A user-delegated OAuth token acts as the user who authorized it. The endpoint must accept user identities, and the user must have the required permissions through their roles and resource access. Accepting OAuth does not make an endpoint available to every signed-in user. Some endpoints, such as status updates, require a user token and are unavailable to public API keys even with full access.

Request-specific checks

An endpoint can support several request forms with different requirements. The filter includes an endpoint when at least one form matches your selection; each endpoint page explains its request-specific requirements.
  • Permissions joined by + are all required. Or separates alternatives.
  • Publishing a workflow requires workflows:deploy as well as workflows:write. Saving a draft only needs the write permission.
  • Ticket archiving requires tickets:archive. Hard-delete requires tickets:admin; tickets:write grants neither.
  • Ticket and message searches without team_ids use an organization-level check. A team-scoped key must supply allowed team IDs.
  • Creating or listing approval delegations with an API key requires delegator_user_id. Omitting it selects the current user, and a key has no user identity.
  • Moving a ticket checks both the source and destination teams. One allowed team is insufficient.
  • Group ownership, entity sharing, ticket settings, and other resource rules can further restrict access.
The filter describes authorization requirements. It does not validate a live token or guarantee that a request will succeed. Expired or revoked credentials, missing resources, invalid parameters, and resource-specific checks can still reject a request.