Skip to content
ajar.Get started
All articles

An API key is not a provider connection

Signing in to ajar, authenticating a request, and connecting a service are three separate steps. Here’s what each one does.

Engineeringajar · 27 September 2026

Three credentials, three jobs

A dashboard session identifies the person using ajar. An API key identifies a request from their code. A provider connection gives the platform access to a particular service account. Treating these as interchangeable makes it difficult to revoke access without breaking something else.

Consider an agent that reads a store menu. The agent needs an ajar API key. It does not need the cookie from your dashboard session, and provider credentials should never be pasted into the tool’s input.

The dashboard session

Sign-in uses an email link or an available OAuth provider. Once signed in, you can manage your workspace and its keys. That browser session is not the credential to put in a script or share with an agent.

Keeping browser access separate means an integration can use its own key without depending on an open browser tab.

The API key

Each key belongs to a workspace. It carries a permission level, a service scope, and any expiry or request limit you chose. A key for one service should not grant access to another.

The identity endpoint reports the workspace, key ID, permission, and scope associated with a key. A successful identity check confirms that the key is accepted. It does not confirm that a provider is reachable or that a particular operation is enabled.

Use a separate key for each integration. When one is exposed or no longer needed, you can revoke that key without replacing every other integration’s credential.

The provider connection

Some operations need access to an account at the underlying service. That connection is distinct from the ajar key. The platform must select an authorized connection for the workspace and operation; the agent should only send the operation’s documented inputs.

A valid ajar key cannot repair an expired provider session. Likewise, a working provider connection should not bypass a revoked ajar key. These checks protect different boundaries.

Where to start

Create a key with the narrowest scope your integration needs. Keep it in a server-side environment variable. Run the API-key example to check it, then read the documentation for the operation you want to call.

If a request fails, first identify which boundary rejected it: ajar authentication, permission for the operation, or the provider connection. Replacing every credential at once makes the original problem harder to find.

Try the API

Check an API key · Sign in · Help center

Still need a hand?

Email us at contact@useajar.com.

Contact us