Authentication and scopes
bk_live_* keys, the key lifecycle and the scope matrix required per operation.
Every request is made with an Authorization: Bearer bk_live_… header. The Developer API only accepts live keys; there is no sandbox key or separate test data path.
Authorization: Bearer bk_live_…Ownership#
The gateway has the Auth service verify the key and forwards only the verified key owner to the Link API. An ownerId, userId or extra scope values in the request body or query cannot change ownership; every query and mutation is limited to the key owner's resources.
Scope matrix#
| Operation | Required scope |
|---|---|
| Reading links, trees, boards, folders and routes; reading QR; platform catalog | links:read |
| Create/update, route condition/target/feature changes, writing QR | links:write |
| Deleting links, trees, boards, folders and route sub-resources | links:delete |
GET /api/v1/links/:id/analytics | analytics:read |
| Reading domain metadata | domains:read |
If a scope is missing, 403 is returned. Undefined public paths are rejected by default (deny-by-default).
Key lifecycle#
| Method | Path | Description |
|---|---|---|
| GET | /v1/developer/api-keys | Metadata list of your keys (no secrets). |
| POST | /v1/developer/api-keys | New key with name, scopes and an optional expiresAt. |
| POST | /v1/developer/api-keys/:id/rotate | Invalidates the old key and issues a new secret with the same scopes/expiry. |
| DELETE | /v1/developer/api-keys/:id | Revokes the key. |
These endpoints are session-protected; the Developer console performs the same operations from the UI. You can have multiple active keys; if expiresAt is not provided, the key never expires.
Do not write the secret to browser storage, logs or URLs. When contacting support, share the X-Request-Id from the response instead of the key.
Is something missing or wrong? Write to the support team; including the X-Request-Id value from the response speeds up the fix.