Skip to main content
All Poelis Public API requests must include a valid REST API key. This page documents the exact request shape; for obtaining keys and operational guidance, see Authentication.

Required Header

Send your REST API key in the Authorization header using Bearer token format:
The key must be sent on every request. There is no session or cookie-based auth.

Scoping

REST API keys are organization-scoped: they grant access to every resource in that organization. Only an organization admin can create a key. Python access uses a separate SDK key, which is limited to what that user can see.

Missing or Invalid Key

If the header is missing or the key is invalid/revoked, the API returns 401 Unauthorized. See Status Codes and Response Format for the canonical error body shape.