Skip to main content

How Authentication Works

The Tented API uses bearer API keys. Each key belongs to exactly one Tented workspace, and every request runs in that workspace’s context. Send your key in the Authorization header:
If the key is valid, Tented resolves the associated workspace internally and authorizes the request for that workspace only.

Creating an API Key

Tented API keys are created inside Tented by a workspace admin.
  1. Ask an admin to create an API key for your workspace.
  2. Copy the raw key when it is shown.
  3. Store it in your secrets manager or environment variables.
Tented only returns the raw API key once at creation time. After that, only key metadata remains visible in the app.

Request Example

Common Authentication Failures

Security Notes

  • Treat the key like a password.
  • Never expose it in browser-side code.
  • Rotate or revoke it if you suspect leakage.
  • Use separate keys for separate systems when you want cleaner auditability.

Workspace Scope

An API key cannot cross workspace boundaries. For example:
  • A tent created with Workspace A’s key cannot be fetched with Workspace B’s key.
  • An asset uploaded with one workspace’s key cannot be attached from another workspace.

Required Headers

Next: Upload Assets

Learn how to attach files to a new or existing tent before generation.