Hawi Developers
Read a workspace from your own code. Three endpoints under /api/v1, two scopes, and keys you issue, scope and rotate yourself. The surface is read-only, and that is stated rather than glossed.
Getting started
- The developer APIThree read-only endpoints, two scopes, bearer authentication, and keys you issue and rotate yourself.
- Your first API requestFrom nothing to a verified key and a real response, in about five minutes.
- AuthenticationKey format, the one moment a secret is visible, expiry options, and rotation.
- Developer consoleIssue a key against a workspace, pick its scopes and expiry, and rotate or revoke it. Inside the product.
Endpoints
- Read a workspaceGET /api/v1/workspaces/{workspaceId} — the fields it returns and the two ways it 404s.
- List workspace filesGET /api/v1/workspaces/{workspaceId}/files — metadata only, paginated, never file content.
- PaginationCursors, the default and maximum page size, and what an invalid cursor does.
- ErrorsThe error shape, every status the API returns, and the header that tells you which of two 401s you hit.
Guides
- Rate limitsTwo stages — one by network origin, one by key — the headers they set, and how to back off.
- Writing a clientRetries, backoff, pagination and the four failures worth handling separately.
- Handling keys safelyWhat a leaked key can and cannot do, and what to do in the first ten minutes.
- WebhooksHow inbound provider events are verified, and why an unverifiable one is dropped.
Resources
- The connector catalogueCustomer-connectable providers from the connector registry.
- External MCP serversPointing an agent at tools you host, and where the trust boundary sits.
- ChangelogWhat shipped, in the order it shipped. The API's own changes are listed with the rest.
- llms.txtA machine-readable index of this site for language models: the primary pages, and how to read the figures on them.
What you are building against
Read a workspace from your own code
Three endpoints under /api/v1: verify a key, read a workspace with its membership, and list its files with signed download links. Cursor pagination, ordinary JSON, ordinary HTTP status codes.
Read-only, and that is the whole surface
There is no write endpoint, no way to start a run and no way to spend money with a key. Anything consequential is released by a person in the product, and an API that could bypass that would be a hole straight through the thing this product is for.
Keys you scope, rotate and revoke
Issue a key against one workspace in the developer console, choose its scopes and how long it lives, and rotate or revoke it there. A key is shown once. Nothing else in the product can read it back.
Limits you can see before you hit them
Every response carries its own remaining budget, and a 429 tells you when to come back. Both ceilings are documented and both are enforced server-side, so a client that respects the headers never has to guess.
Reporting pipeline
hawi_sk_live_••••••••••••••••3f92
workspace:readWorkspace metadata and membershipfiles:readFile listings and signed download linkscontrol-center:readAgents, pending approvals and service healthanalytics:readRun counts, usage and spendapprovals:writeResolving a pending approvalagents:writeChanging an agent's control mode
X-RateLimit-Limit300per key, per minuteX-RateLimit-Remaining287counts down in the responseRetry-After12seconds, only on a 429
A second ceiling of 600 a minute applies per network, before the key is read.
Every endpoint is read-only. There is no write surface to reach with a key.
Both panels are drawn from the product: the scopes and expiry options come from the same module the console validates against, and the limits are the figures in the routes themselves.