Developers
Authentication
Every API and MCP request is authenticated with a workspace API key sent as a bearer token.
Sending the key
Authorization: Bearer wf_live_…
Create keys in Settings → API keys. Keep them out of source control — read them from an environment variable, as the examples here do with $WEBFORGIA_API_KEY.
What a key can do
- One workspace. The workspace comes from the key; no endpoint takes a workspace argument.
- Scopes.
read,writeandpublish, checked on every request. See API Keys. - Expiry. A key can be given an expiry date, after which it stops working; a workspace can require one.
If a key leaks
Revoke it in Settings → API keys at once — it stops working immediately — and create a replacement. Revoking is recorded in the audit log. Keys are stored only as hashes, so Webforgia cannot show or recover a lost key; you create a new one.