Authentication
The REST API uses the same API keys as AI / Agent access. Mint a key, then send it as a bearer token.
Get a key
Section titled “Get a key”Create an API key in Settings → Connections → API & agent access in the Assemblified admin — the same API keys for REST and your own agent card that serves desktop and CLI AI assistants. The full walkthrough (labels, the one-time reveal, revoking) lives in the Agent-access docs:
Scopes
Section titled “Scopes”Pick the key’s scope when you create it:
| Scope | What it allows over REST |
|---|---|
| Read only | Every GET endpoint — materials, inventory, bills of materials, order breakdowns, work orders, locations, assignees, bill versions. |
| Read & write | Everything a read key can, plus the five PATCH endpoints: edit a virtual material, set a virtual material’s per-location stock, edit a work order’s header, move a work order to another state, and start a build run. |
A PATCH with a read-only key returns 403 FORBIDDEN_SCOPE. A key keeps the scope it was created with; to change it, revoke the key and mint a new one.
Send the token
Section titled “Send the token”Put the key in the Authorization header:
curl -s -H "Authorization: Bearer asmk_xxxxxxxx" \ "https://assemblified.com/api/v1/raw-materials"- A missing or invalid token returns
401immediately — before any data is touched. - A revoked key returns
401. Revoke in Settings → API & agent access at any time. - The key identifies your shop on its own; there is no shop id in the URL.
Managing access
Section titled “Managing access”Each request is recorded in the audit log (tagged rest:), so you can see which key made which call. Manage and revoke keys from Settings → API & agent access.