Semogram Docs
APIUsing the API

Authentication and scopes

Authenticate a service and constrain its workspace, projects and reads

Create a workspace API key using a Semogram account with administrative access, or an existing workspace-wide org:manage key. Store the secret when it is returned; later key listings do not recover it.

Send Authorization: Bearer YOUR_API_KEY on consumer requests. Use HTTPS and your service's secret store. Do not put the key in a URL or share it in an assistant prompt. Public pricing is unauthenticated; the Stripe webhook uses Stripe signature verification instead of this credential.

Authorization layers

LayerMeaning
WorkspaceA key belongs to one workspace
ScopeAllows an operation family, such as pipelines:execute
Project allowlistRestricts project-scoped resources
Workspace resource accessExplicit access to shared workspace resources for restricted keys
Named read grantsSatisfies permissions required by ontology bindings
Accountable actor and policyAdditional requirements for authoring, execution and governed changes

A scope does not install a connector, grant database access or approve a write. A project allowlist does not automatically grant all workspace endpoints. org:manage is administrative access and cannot be project-restricted; use narrower keys for consumers.

Select scopes by task

TaskScopes
Discover workspace/projectorg:read, projects:read
Execute and inspect pipelinepipelines:execute, runs:read; add pipelines:read to inspect configuration
Read endpoint recordsdata:read, with workspace resource access
Execute published queryqueries:execute, plus any required named binding grants
Manage queries/releasesqueries:read, queries:write, queries:publish as appropriate
Inspect ontology/bindingsontologies:read, bindings:read
Administer workspaceWorkspace-wide org:manage

The route catalog records the gate used by each route. Some operations also require current member permissions. Revocation, expiry or loss of the accountable actor can invalidate a previously working integration.

Verify a key

curl --fail-with-body -H "Authorization: Bearer $SEMOGRAM_API_KEY" \
  'https://platform.semogram.com/api/v1/organization'

This requires org:read and returns { "organization": ... }. If the consumer key intentionally lacks this scope, verify its intended resource action instead. See API key administration for the platform setup and rotation flow.