Overview and authentication
Base URL, API keys, scopes, errors and rate limits for the dock API.
What you will do: create an API key for your organization and make a first authenticated call.
The dock API is an HTTPS, JSON API. Every request is made on behalf of an organization and is authorised by an API key with scopes. The endpoint reference pages — deployments, licenses, usage, webhooks — are available when you sign in.
Base URL
https://<placeholder-api-host>/<placeholder-version>
Create an API key
- In your workspace, open Integrations and choose API keys.
- Choose Create key, name it after the system that will use it, and select scopes:
Scopes: <placeholder>
- Copy the key once. It is not shown again; create a new one if it is lost.
- Keys can be revoked from the same page. Revoking is immediate.
Authenticate
Send the key as a bearer token:
curl -H "Authorization: Bearer <placeholder-api-key>" \ https://<placeholder-api-host>/<placeholder-version>/<placeholder-resource>
Conventions
- Format. Requests and responses are JSON. Timestamps are ISO 8601 in UTC.
- Pagination. List endpoints return a page and a cursor for the next one.
- Errors. Standard HTTP status codes with a JSON body that carries a stable error code and a message.
Error body: <placeholder>
- Rate limits. Requests over the limit receive a 429 response and a header saying when to retry.
Rate limit: <placeholder>
- Versioning. The version is part of the base URL. Breaking changes ship as a new version; older versions stay available for a published period.
Idempotency
Create calls accept an idempotency key header so that a retried request does not create a second deployment or subscription.
Next
Sign in to read the endpoint pages: Deployments API, Licenses API, Usage API and Webhooks.
Next: Security and compliance
Verify with XPLG engineering before publishing.