Gateway authentication
Authenticate tenant gateway calls.
The public gateway accepts either Authorization bearer keys or X-API-Key headers and routes reads to the selected account slug.
Steps
- Create or rotate a tenant API key in the portal.
- Call the account-specific gateway route for multi-account tenants.
- Send the key with either an Authorization bearer header or an X-API-Key header.
- Keep keys out of browser-visible pages, logs, issue reports, and committed files.
Prerequisites
- A dataz.md workspace with an activated account slot.
- A tenant API key created in the portal.
- Access to data the connected provider account can read.
API paths used
GET /v1/{tenant_slug}/accounts/{account_slug}/...
Authorization: Bearer <key>
X-API-Key: <key>
Limitations
- Old provider-in-path routes still work, but new integrations should use the account-slug route.
- Gateway calls are read-only and reject mutating methods.
- Setup/token, AI, dev, and internal prefixes are not public gateway surfaces.
Check the reference details.
Use the endpoint reference for parameters, response schemas, and tenant gateway notes.