Skip to main content
Every API operation under https://api.entendre.finance/v1 needs a credential. Send all requests over HTTPS.
Create a key in Organization → API in the Entendre dashboard. Choose All access or Read only. A read-only key cannot call write operations.
Your organization is inferred from the key. You do not need to send an organization ID.
Create a firm key in Firm Settings → API. To call a client’s data, send the client’s organization ID in the organization-id header. If you omit the header, the key uses its default client. A key without a default client can call firm operations only.

API key owner

A key has an owner when a user creates it. Operations that record who made a change, or that open a document, need an API key with an owner. Other keys receive HTTP 403.

Authentication errors

A missing, invalid or expired credential returns 401 with error.code set to UNAUTHORIZED:
A 401 has a WWW-Authenticate: Bearer header. Its resource_metadata parameter gives the URL of the protected resource metadata. It also has error="invalid_token" when the credential that you sent is invalid or expired. A valid credential without the required access returns 403 with error.code set to FORBIDDEN. Firm keys have more responses; see Firm API keys above. See Errors for other failures.

Keep credentials safe

Keep keys and tokens out of browser code and version control. Store them in a secrets manager or in environment variables. If a key is exposed, select Revoke key in the dashboard and create a new one.