Before you authenticate
You need an active WEXTL account with at least one organization. Mint a Personal Access Token from Dashboard → API, or complete an OAuth sign-in instead if your client supports it.[1]
Personal Access Tokens (PAT)
Mint a token from Dashboard → API and send it as a bearer credential on every request. A token acts on behalf of the member who created it — actions taken with it are attributed to "{creator} via API key {name}" in your organization's activity log.
Authorization: Bearer wextl_...OAuth 2.1
Hosted AI clients (claude.ai, ChatGPT) connect via OAuth 2.1 with dynamic client registration instead of a pasted token. You approve an organization + scope grant once during the consent flow; the client then holds a short-lived access token it refreshes automatically.
Scope model
Every scope is a pair of an entity type (workflow, credential, database, variable, structure, function, activity, invitation) and an action (read or write). Grant the narrowest set of scopes a token needs — a read-only integration should never hold a write scope it doesn't use. Team and folder discovery tools use workflow:read; webhook minting uses workflow:write.
- Least privilege: pick read-only scopes whenever your integration only inspects data.
- Per-stage checks: some actions (e.g. using a credential for live options) require credential:use-level write, not just credential:read.
- When create_credential returns a connect_url, a logged-in org member completes the form; the agent then polls list_credentials.
Rotating a key
Rotate a Personal Access Token without downtime by following these steps in order. The per-organization key cap allows both tokens to exist briefly during the cut-over:
- Mint a new Personal Access Token.
- Update your integration to use the new token.
- Confirm calls succeed with the new token.
- Revoke the old token.
Working across multiple organizations
A key or OAuth grant is scoped to exactly one organization and its regional endpoint. To integrate with N organizations, mint N tokens (or complete N OAuth grants) — one connection per organization.
Offboarding a member
When a member who granted an OAuth connection leaves the organization or is demoted below admin, their grants stop working the next time they're used — access is re-checked against their current role on every request, so there's nothing extra to revoke by hand.
References
- WEXTL® authentication and scope-check implementation.
- Our users' real API keys and OAuth grants in use.
- OAuth 2.1 specification.