Authentication

API keys, scopes, and which routes you can use with a key and which are dashboard-only.

Updated:

API keys

Keys are created by the owner in Settings → Developers. They are shown once. Send your key as a bearer token:

GET /v1/me HTTP/1.1
Host: api.wagend.app
Authorization: Bearer wg_live_xxxxxxxx_xxxxxxxxxxxxxxxxxxxx
PrefixMode
wg_live_Production data and real messages
wg_test_Read-only: it can list and read, not create or change anything. A sandbox for writes is Coming soon

Keys belong to one project (workspace). The project always comes from the key: there is no workspace id in paths or bodies. Keys are stored hashed.

Scopes

ScopeAllows
slots:readGET /slots
bookings:readRead bookings and tasks (/bookings, /work-items), stage history, attachments, team statistics
bookings:writeHolds, confirm, cancel, reschedule, check-in, no-show, complete, run actions and edit a task's priority, tags and due date
customers:readRead and search customers, their history, summary and comments
customers:writeCreate and edit customers
messages:readRead conversations and messages
messages:writeSend messages, switch the mode (bot or person), resolve, mark as read
config:read / config:writeServices, resources, groups, schedules, rule-based automations, knowledge and bot
settings:writeReplace and revert stages, actions and forms (/stage-config)
webhooks:manageOutgoing webhook endpoints

A request without the needed scope returns 403 with code: "insufficient_scope".

What is dashboard-only

These areas do not accept API keys: they use the session of a team member (with their role) and are protected with CSRF. If you call them with a key, the API answers that they are not available for that type of credential.

  • Channels, channel and AI pauses, service status.
  • Automation flows (/automation-flows), the Wagy assistant and its plan.
  • Knowledge sources (/knowledge/sources) and the per-channel bot policy.
  • Team, invitations, API keys, projects and platform support.
  • Team Telegram and alert preferences.

The endpoint list marks which is which.

Rotation

Create a new key, deploy it, then revoke the old one in Settings → Developers. Revoked keys return 401 immediately.