Skip to main content
API v2 accepts an API token as a bearer credential:
  • Create a token on the Agents page, or get one with OAuth device login.
  • A token can do only what its scopes, its chatbot access, and your dashboard role allow.
  • Each endpoint page in this reference lists the scopes that the operation needs.
  • The legacy API key from the Billing page does not work with API v2. The only exception is GET /api/v2/me, which accepts it and returns a warning.
Authentication is the full reference. It covers token creation, access levels, the scope table, OAuth device login, and the legacy API key.

Authentication errors

A 401 response includes a WWW-Authenticate header that points to https://sitegpt.ai/.well-known/oauth-protected-resource/api/v2. See API conventions for all error codes.