Authentication
API keys, scopes and rate limits.
API keys
Create keys in the dashboard under API Keys. Each key belongs to your organization, carries a set of scopes, and can have an expiry date. The full key is shown once, when you create it; after that the dashboard only shows its prefix. Revoke a key from the same page.
Send the key on every request, either as a bearer token:
Authorization: Bearer org_xxxxxxxx_…or in the X-API-Key header:
X-API-Key: org_xxxxxxxx_…Keep keys on your server. Anyone holding a key can act as your organization within its scopes.
A key acts with the access of the dashboard user who created it. For example, the tickets and messages it can read are the ones that user can see.
Scopes
Give each key only the scopes it needs. A request without the required scope fails with 403.
| Scope | Allows |
|---|---|
message:send | Send templates, text, buttons and media |
message:read | Read conversation history |
tickets:create | Create tickets |
tickets:read | List and read tickets |
tickets:update | Update tickets |
conversation:handover:request | Hand a conversation to human agents; read session messages |
conversation:handover:open | Hand a conversation back to the bot |
mcp:access | Use the MCP gateway |
Check a key
GET /v1/api-keys/me returns the key's organization, scopes and expiry. It needs no scope, so
it is a quick way to test a key:
curl https://api.enigma-ai.com/v1/api-keys/me -H "Authorization: Bearer $ENIGMA_API_KEY"{
"keyId": "6650a1b2c3d4e5f6a7b8c9d0",
"organizationId": "664f0a1b2c3d4e5f6a7b8c9d",
"scopes": ["message:send", "tickets:create"],
"expiresAt": null
}Rate limits
Each endpoint allows 60 requests per minute per key. Beyond that, requests fail with 429
and a message saying how many seconds to wait.