Skip to main content
All product API routes use bearer authentication and workspace-scoped authorization. Mutations that support replay protection accept a stable Idempotency-Key; propagate X-Correlation-ID through your own logs.
These examples use standard HTTP clients and match the generated OpenAPI 3.1 contract. Generated SDK packages should pin the committed openapi.json digest and expose the same errors and idempotency behavior.
Last modified on July 28, 2026