Authentication

One key, three layers of permission. Everything the key can do is exactly what its owner could do in the UI — nothing more.

Manage API keys

Create

Settings → API keys → New key. Pick a name, the apps it may touch, and an expiry. The secret is shown once.

Rotate

Rotate any key with zero downtime: the old secret stays valid for a 24-hour grace period while you deploy the new one.

Revoke

Revoke instantly from the same page. In-flight requests finish; new requests get 401 immediately.

Bearer authentication

Every request carries Authorization: Bearer <key>. The gateway binds the key to its user (user_id + organization_id) and injects the permission context into the request — no per-call identity parameters needed.

cURL
curl https://api.bodegito.com/v1/oms/orders?page_size=5 \
  -H "Authorization: Bearer $BODEGITO_API_KEY"

Permissions

Keys inherit the owner's three layers: app access (which of the six apps), feature permissions (read vs write per module), and data scope (warehouses, merchants). A 403 means the key — like its owner — is not allowed there.

IP allowlist (reserved)

Pin a key to specific egress IPs for extra safety. Coming soon — the API surface is ready, the UI is not.