Send the API key
Use either authentication method. Both carry the same Organization API key.- x-api-key
- Bearer
Send one authentication header per request. You do not need to send both.
Authentication errors
A missing, invalid, or expired API key returns401 Unauthorized.
Secure key handling
- Store API keys in a server-side secrets manager or protected environment variable.
- Never commit keys to a repository.
- Never expose keys in browser or mobile client code.
- Never include keys in URLs, screenshots, or application logs.
- Rotate the key from Jitra if it is exposed or compromised.
- Use separate keys for separate integrations when your Organization’s setup allows it.
