API Docs
Authentication

Team API keys

Authenticate server-to-server calls with a key scoped to your own team.

All endpoints require Bearer token authentication. The simplest token is a team API key.

Create a key

Go to Dashboard → Integrations → API keys and create a key. Store it in your secret manager; it is shown once.

Use it

Send the key on every request:

curl "https://www.talentir.com/api/v2/team" \
  -H "Authorization: Bearer $TALENTIR_API_KEY"

API key access is scoped to the team that owns the key. To act on behalf of other teams (your customers), use OAuth 2.1 instead.

Scopes

A new key carries every freely grantable scope: read and write payouts, counterparties, webhooks, and sessions, and read team information. Scopes are fixed when a key is created, so a key created before a scope existed must be edited (or replaced) to receive it. Keys created before v2 have no counterparties:read or counterparties:write.

The payouts:approve scope is restricted: it is only granted to keys of teams with the payout.api_approve permission. See Scopes and permissions.

Good practice

  • Keys are environment-specific: a sandbox key does not work in production.
  • Rotate keys from the dashboard; deleting a key revokes it immediately.
  • Never embed keys in client-side code. Calls belong on your server.