Enigma Developers

Authentication

API keys, scopes and rate limits.

API keys

Create keys in the dashboard under API Keys. Each key belongs to your organization, carries a set of scopes, and can have an expiry date. The full key is shown once, when you create it; after that the dashboard only shows its prefix. Revoke a key from the same page.

Send the key on every request, either as a bearer token:

Authorization: Bearer org_xxxxxxxx_…

or in the X-API-Key header:

X-API-Key: org_xxxxxxxx_…

Keep keys on your server. Anyone holding a key can act as your organization within its scopes.

A key acts with the access of the dashboard user who created it. For example, the tickets and messages it can read are the ones that user can see.

Scopes

Give each key only the scopes it needs. A request without the required scope fails with 403.

ScopeAllows
message:sendSend templates, text, buttons and media
message:readRead conversation history
tickets:createCreate tickets
tickets:readList and read tickets
tickets:updateUpdate tickets
conversation:handover:requestHand a conversation to human agents; read session messages
conversation:handover:openHand a conversation back to the bot
mcp:accessUse the MCP gateway

Check a key

GET /v1/api-keys/me returns the key's organization, scopes and expiry. It needs no scope, so it is a quick way to test a key:

curl https://api.enigma-ai.com/v1/api-keys/me -H "Authorization: Bearer $ENIGMA_API_KEY"
{
  "keyId": "6650a1b2c3d4e5f6a7b8c9d0",
  "organizationId": "664f0a1b2c3d4e5f6a7b8c9d",
  "scopes": ["message:send", "tickets:create"],
  "expiresAt": null
}

Rate limits

Each endpoint allows 60 requests per minute per key. Beyond that, requests fail with 429 and a message saying how many seconds to wait.

On this page