Skip to main content
Every Jitra Public API endpoint requires an API key issued for your Organization.

Send the API key

Use either authentication method. Both carry the same Organization API key.
Send one authentication header per request. You do not need to send both.

Authentication errors

A missing, invalid, or expired API key returns 401 Unauthorized.

Secure key handling

  • Store API keys in a server-side secrets manager or protected environment variable.
  • Never commit keys to a repository.
  • Never expose keys in browser or mobile client code.
  • Never include keys in URLs, screenshots, or application logs.
  • Rotate the key from Jitra if it is exposed or compromised.
  • Use separate keys for separate integrations when your Organization’s setup allows it.
An API key grants access to data available to its Organization. Treat it as a production secret.