Skip to main content
Skip to content

Hawi Developers

Read a workspace from your own code. Three endpoints under /api/v1, two scopes, and keys you issue, scope and rotate yourself. The surface is read-only, and that is stated rather than glossed.

Getting started

Endpoints

Guides

Resources

What you are building against

Read a workspace from your own code

Three endpoints under /api/v1: verify a key, read a workspace with its membership, and list its files with signed download links. Cursor pagination, ordinary JSON, ordinary HTTP status codes.

Read-only, and that is the whole surface

There is no write endpoint, no way to start a run and no way to spend money with a key. Anything consequential is released by a person in the product, and an API that could bypass that would be a hole straight through the thing this product is for.

Keys you scope, rotate and revoke

Issue a key against one workspace in the developer console, choose its scopes and how long it lives, and rotate or revoke it there. A key is shown once. Nothing else in the product can read it back.

Limits you can see before you hit them

Every response carries its own remaining budget, and a 429 tells you when to come back. Both ceilings are documented and both are enforced server-side, so a client that respects the headers never has to guess.

Developer console

Reporting pipeline

hawi_sk_live_••••••••••••••••3f92

Active
  • workspace:readWorkspace metadata and membership
  • files:readFile listings and signed download links
  • control-center:readAgents, pending approvals and service health
  • analytics:readRun counts, usage and spend
  • approvals:writeResolving a pending approval
  • agents:writeChanging an agent's control mode
Expires in7d30d90d365d
Every response
  • X-RateLimit-Limit300per key, per minute
  • X-RateLimit-Remaining287counts down in the response
  • Retry-After12seconds, only on a 429

A second ceiling of 600 a minute applies per network, before the key is read.

Every endpoint is read-only. There is no write surface to reach with a key.

Both panels are drawn from the product: the scopes and expiry options come from the same module the console validates against, and the limits are the figures in the routes themselves.