Skip to main content
Every request to a data endpoint carries an Xpoz access key in the Authorization header:
Get a key from xpoz.ai/get-token or create one with POST /api/tokens from a signed-in dashboard session. Keys are the same ones used by the MCP server, the SDKs, and the CLI. See Authentication for the full picture across interfaces.

Two security schemes

The spec declares two bearer schemes. Each endpoint’s reference page shows which one it expects. Only the access key scheme is meant for integrations. The session scheme exists because the Xpoz dashboard calls the same API, and those endpoints appear in the reference so the spec is complete.

Example

Failure responses

Trying endpoints from the docs

Each endpoint page has a request builder. Paste your access key into its authorization field once and it is reused across pages in this browser session. The same applies to the Authorize button on the Swagger UI.