API key issued at onboarding. Passed as a Bearer token in the Authorization header: Authorization: Bearer <api-key>. Identifies the caller and determines organization scope. Invalid or revoked keys return 401 with error type authentication_error.
Ed25519 or RSA-SHA256 asymmetric signature over the request payload (ADR-0015). Provides request integrity and non-repudiation. The signature covers the HTTP method, path, query string, request body, and timestamp. Invalid signatures return 401 with error type authentication_error.
Unix timestamp (seconds) of when the request was signed. Server rejects requests where the timestamp drifts beyond +/-60 seconds from server time to prevent replay attacks. Must match the timestamp used in the signature computation.
Maximum number of items to return. Default 50, max 200.
1 <= x <= 200Cursor for forward pagination. Return items created after the item with this ID. Mutually exclusive with ending_before.
Cursor for backward pagination. Return items created before the item with this ID. Mutually exclusive with starting_after.
Filter items created at or after this timestamp.
"2026-01-01T00:00:00Z"
Filter items created at or before this timestamp.
"2026-12-31T23:59:59Z"