openstead
API

Authentication

Create scoped API keys and understand workspace permissions for automation.

Suggest a change

Openstead API keys authorize access to one workspace. Keep them in your server environment or CI secret store.

Create a key

  1. Sign in to the Openstead dashboard.
  2. Open Account settings → API Keys → Create API key.
  3. Enter a descriptive name, select the workspace, choose the scope, and choose an expiry.
  4. Copy the displayed key into a secret store. The complete value is shown when created.

Use a separate key for each integration so you can revoke it without interrupting unrelated systems.

Send the key

curl --fail-with-body \
  --header "Authorization: Bearer $OPENSTEAD_API_KEY" \
  "https://api.openstead.tech/api/v1/catalog"

Keys begin with rnv_. Pass the exact Bearer scheme and key in the header. Do not put a key in a URL, commit it to Git, or embed it in a frontend bundle. The TypeScript SDK belongs in server code, including a Next.js Route Handler or server-only module.

Scopes and roles

ScopeAccess
Read onlyRead resources available to your workspace role.
Read and writeRead and mutate resources within your workspace role.

Scope does not grant a higher role. Developers can manage ordinary services and request deployments. Project deletion and changes to services in protected environments require an admin or owner. Current membership, account status, verified email, and any workspace MFA policy are checked on requests, including idempotent replays.

A key from one workspace cannot read a different workspace. There is no workspace-list or workspace-create operation in the public core contract; use the workspace ID associated with your key.

Create a paid service configuration with deploy: false, complete its checkout in the dashboard, then deploy it with your API key. A key can manage deployments within an authorized service term. It cannot purchase a term, charge a payment method, or provide payment consent.

Rotate or revoke access

Create a replacement key, update your secret store, verify a read request, and revoke the old key from API Keys. Expired or revoked keys stop working. Removing the key owner's membership also removes their access.

The CLI offers browser-assisted sign-in and stores its credential in the operating system keychain. It uses the same workspace permissions.

Diagnose authentication failures

  • 401 invalid_api_key: verify the value, expiry, and whether it was revoked.
  • 403 insufficient_scope: check both the key's scope and workspace ID.
  • 403 email_verification_required: verify your account email.
  • 403 mfa_required: enable the MFA required by the workspace.
  • 403 permission_denied: ask a workspace owner to review your role or the environment's protection.

Browser session cookies are for dashboard interactions. Use bearer keys for SDK, CI, and server integrations; a validated bearer key does not require a CSRF token.

Need a hand? Contact Openstead support.

On this page