- Create a token on the Agents page, or get one with OAuth device login.
- A token can do only what its scopes, its chatbot access, and your dashboard role allow.
- Each endpoint page in this reference lists the scopes that the operation needs.
- The legacy API key from the Billing page does not work with API v2. The only exception is
GET /api/v2/me, which accepts it and returns a warning.
Authentication errors
A
401 response includes a WWW-Authenticate header that points to https://sitegpt.ai/.well-known/oauth-protected-resource/api/v2. See API conventions for all error codes.