Skip to content
ajar.Get started
All examples

Check an API key

Make one authenticated request and see which workspace and permissions the key belongs to.

GET /v1/identitycURL / Node.js / Python

1. Set up

Create an API key in your workspace. In your terminal, set AJAR_API_URL to the API base URL for your environment and AJAR_API_KEY to the secret. Use HTTPS for a remote API.

Run these examples on your machine or server. Do not put the secret in browser code or commit it to a repository.

The cURL example needs cURL 7.76 or later. The JavaScript example uses Node.js 22 or later; the Python example uses Python 3.10 or later. Neither needs an installed package.

2. Send the request

Download the script, then run sh check-api-key.sh, node check-api-key.mjs, or python3 check_api_key.py.

#!/usr/bin/env sh
set -eu

: "${AJAR_API_URL:?Set AJAR_API_URL to your API base URL}"
: "${AJAR_API_KEY:?Set AJAR_API_KEY to your API key}"

curl --fail-with-body --silent --show-error \
  --max-time 15 \
  "${AJAR_API_URL%/}/v1/identity" \
  -H "Authorization: Bearer $AJAR_API_KEY"
check-api-key.shDownload

3. Read the response

A successful response has this shape. IDs, permission, and scope will match your key.

{
  "workspaceId": "<workspace ID>",
  "keyId": "<key ID>",
  "permission": "read",
  "scope": "starbucks"
}

workspaceId identifies the workspace. keyId identifies the key without revealing its secret. permission and scope describe its configured access.

This request counts against the key’s request limit. A successful check confirms ajar authentication; it does not check a provider connection or enable additional operations.

If it fails

For a 401, check the key and its expiry. For a 403, check account and workspace access. For a 429, stop and review the key’s request limit before trying again.

Troubleshoot a rejected request →