Skip to main content
Use an Effective user API key issued for the tenant you intend to access. If you do not have one, ask your Effective administrator to provision it. Send the key in the Authorization header of each request:
Keep the key in an environment variable or your application’s secret store. Do not put it in URLs, committed source files, or shared transcripts. The key determines the authenticated user and tenant. The current-user response’s tenantId lets you verify which tenant you are using. V2 currently supports ordinary user API keys. Record-bot, scoped user, and app-specific credentials have separate access restrictions and are not a substitute for a user API key on this endpoint.

Authentication failures

API-generated v2 errors return a human-readable error and a stable code:
  • 401 Unauthorized: credentials are missing, invalid, expired, revoked, or unsupported on this endpoint. Check the key before retrying.
  • 403 Forbidden: the authenticated credential does not permit the operation. Use a credential with the appropriate access.
Use code and HTTP status for control flow, not message text. Unknown future codes fall back to HTTP status. Errors may also include requestId for support and bounded details for invalid input; both are optional. Authentication can fail before a request ID is available. V2 responses use Cache-Control: private, no-store.