Overview
The 2026-05-01 API authenticates requests via the standardAuthorization header with a bearer token. You can view and manage your API keys in the Augustus Dashboard.
API keys
Set your API key in theAuthorization header on every request:
Key format
API keys are prefixed with their environment (e.g.sandbox., prod.) so you can immediately identify which environment a key belongs to. Keys are otherwise opaque. Treat them as a single string.
Environments
Sandbox and production are isolated. API keys and resources created in one environment are not accessible in the other.
Key scopes
Each API key carries one or more scopes that gate which resources and actions it can use. See Scopes for the full catalogue, alias semantics, and recommended scope sets for common integration patterns.IP allowlisting
When you create an API key in the Dashboard, you can optionally restrict it to one or more IP addresses or CIDR ranges (IPv4 and IPv6). Requests authenticated with that key are then accepted only from an allowlisted address; requests from any other address are rejected with403 permission_denied. A key without an allowlist is not IP-restricted. The allowlist is returned as ip_allow_list on the API key resource (GET /v1/api_key).