Skip to main content

Send your API key

The production API base URL is https://api.protodesk.io/v1. Send your key in the Authorization header:
Keys are bound to one workspace. Use GET /me to inspect the workspace and scopes before writing data. Public API requests do not need X-Workspace-Id.

Choose permissions

Create and manage keys in Settings → API. Grant the permissions your integration needs. This table covers the workflows in these guides. A permission name alone does not guarantee a public endpoint; use the API reference to check endpoint availability. API key management endpoints require keys:manage.

Help Center access

An owner or admin grants Help Center access and confirms that article content may be shared with the connected AI tool. Help-enabled keys have an expiry between 1 and 90 days. If a key combines Help Center and other permissions, expiry applies to the whole key. Proposal permission allows an assistant to submit changes for review. It does not let the assistant approve proposals or publish articles.

Store and rotate secrets

Keep keys in server-side configuration or a secret manager. Never expose a key in a browser bundle. Create a replacement key, update your integration, verify a request, then revoke the old key from the dashboard. The pk_live_ and pk_test_ prefixes identify key mode. They do not isolate workspace data into production and sandbox databases.

Troubleshoot access

  • 401: Check the Bearer header, secret, expiry, and whether the key was revoked.
  • 403: Check the key’s scopes and whether the operation is allowed for that connection.
  • Wrong workspace: Stop writes and select the correct workspace before creating a replacement key.