Draft

Authentication

API keys, scopes, test and live modes.

API keys

Send your key as a bearer token:

GET /v1/me HTTP/1.1
Host: api.wagend.app
Authorization: Bearer wg_live_3fa9c2_Lr8t...
PrefixMode
wg_live_Production data, real messages and payments
wg_test_Sandbox: isolated data, no messages sent, simulated payments

Keys belong to one workspace. The workspace is always taken from the key: there is no workspace id in paths or bodies. Keys are stored hashed; the full key is shown only once at creation.

Scopes

ScopeAllows
slots:readGET /slots
bookings:readList and read bookings
bookings:writeHolds, confirm, cancel, reschedule, check-in, no-show
customers:readRead customers
messages:readRead conversations and messages
messages:writeSend messages, hand over
config:read / config:writeServices, resources, groups, schedules, automations, knowledge
webhooks:manageWebhook endpoints

A request without the needed scope returns 403 with code: "insufficient_scope".

Rotation

Create a new key, deploy it, then revoke the old one in Developers → API keys. Revoked keys return 401 immediately.