Draft
Authentication
API keys, scopes, test and live modes.
API keys
Send your key as a bearer token:
GET /v1/me HTTP/1.1
Host: api.wagend.app
Authorization: Bearer wg_live_3fa9c2_Lr8t...
| Prefix | Mode |
|---|---|
wg_live_ | Production data, real messages and payments |
wg_test_ | Sandbox: isolated data, no messages sent, simulated payments |
Keys belong to one workspace. The workspace is always taken from the key: there is no workspace id in paths or bodies. Keys are stored hashed; the full key is shown only once at creation.
Scopes
| Scope | Allows |
|---|---|
slots:read | GET /slots |
bookings:read | List and read bookings |
bookings:write | Holds, confirm, cancel, reschedule, check-in, no-show |
customers:read | Read customers |
messages:read | Read conversations and messages |
messages:write | Send messages, hand over |
config:read / config:write | Services, resources, groups, schedules, automations, knowledge |
webhooks:manage | Webhook endpoints |
A request without the needed scope returns 403 with code: "insufficient_scope".
Rotation
Create a new key, deploy it, then revoke the old one in Developers → API keys. Revoked keys return 401 immediately.