> ## Documentation Index
> Fetch the complete documentation index at: https://docs.protodesk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication and permissions

> Authenticate server-side requests with a scoped workspace API key.

## Send your API key

The production API base URL is `https://api.protodesk.io/v1`. Send your key in the `Authorization` header:

```http theme={null}
Authorization: Bearer YOUR_API_KEY
```

Keys are bound to one workspace. Use `GET /me` to inspect the workspace and scopes before writing data. Public API requests do not need `X-Workspace-Id`.

## Choose permissions

Create and manage keys in **Settings → API**. Grant the permissions your integration needs.

| Scope | Purpose |
| - | - |
| `customers:read` / `customers:write` | Read or manage customers and channel identities |
| `conversations:read` / `conversations:write` | Read conversations and their messages, or manage conversations |
| `messages:write` | Create messages |
| `webhooks:manage` | Manage webhook subscriptions and inspect deliveries |
| `realtime:read` | Read the workspace event stream |
| `help:read` | Read authorized Help Center articles, including drafts |
| `help:drafts:write` | Submit Help Center content proposals; requires `help:read` |

This table covers the workflows in these guides. A permission name alone does not guarantee a public endpoint; use the API reference to check endpoint availability. API key management endpoints require `keys:manage`.

## Help Center access

An owner or admin grants Help Center access and confirms that article content may be shared with the connected AI tool. Help-enabled keys have an expiry between 1 and 90 days. If a key combines Help Center and other permissions, expiry applies to the whole key.

Proposal permission allows an assistant to submit changes for review. It does not let the assistant approve proposals or publish articles.

## Store and rotate secrets

Keep keys in server-side configuration or a secret manager. Never expose a key in a browser bundle. Create a replacement key, update your integration, verify a request, then revoke the old key from the dashboard.

The `pk_live_` and `pk_test_` prefixes identify key mode. They do not isolate workspace data into production and sandbox databases.

## Troubleshoot access

* **401:** Check the Bearer header, secret, expiry, and whether the key was revoked.
* **403:** Check the key's scopes and whether the operation is allowed for that connection.
* **Wrong workspace:** Stop writes and select the correct workspace before creating a replacement key.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.