Authentication
API keys, scopes, and which routes you can use with a key and which are dashboard-only.
Updated:
API keys
Keys are created by the owner in Settings → Developers. They are shown once. Send your key as a bearer token:
GET /v1/me HTTP/1.1
Host: api.fiuit.com
Authorization: Bearer wg_live_xxxxxxxx_xxxxxxxxxxxxxxxxxxxx
| Prefix | Mode |
|---|---|
wg_live_ | Production data and real messages |
wg_test_ | Read-only: it can list and read, not create or change anything. A sandbox for writes is Coming soon |
Keys belong to one project (workspace). The project always comes from the key: there is no workspace id in paths or bodies. Keys are stored hashed.
Scopes
| Scope | Allows |
|---|---|
slots:read | GET /slots |
bookings:read | Read bookings and tasks (/bookings, /work-items), stage history, attachments, team statistics |
bookings:write | Holds, confirm, cancel, reschedule, check-in, no-show, complete, run actions and edit a task's priority, tags and due date |
customers:read | Read and search customers, their history, summary and comments |
customers:write | Create and edit customers |
messages:read | Read conversations and messages |
messages:write | Send messages, switch the mode (bot or person), resolve, mark as read |
config:read / config:write | Services, resources, groups, schedules, rule-based automations, knowledge and bot |
settings:write | Replace and revert stages, actions and forms (/stage-config) |
webhooks:manage | Outgoing webhook endpoints |
A request without the needed scope returns 403 with code: "insufficient_scope".
What is dashboard-only
These areas do not accept API keys: they use the session of a team member (with their role) and are protected with CSRF. If you call them with a key, the API answers that they are not available for that type of credential.
- Channels, channel and AI pauses, service status.
- Automation flows (
/automation-flows), the Wagy assistant and its plan. - Knowledge sources (
/knowledge/sources) and the per-channel bot policy. - Team, invitations, API keys, projects and platform support.
- Team Telegram and alert preferences.
The endpoint list marks which is which.
Rotation
Create a new key, deploy it, then revoke the old one in Settings → Developers. Revoked keys return 401 immediately.