Authentication
API key, JWT, or HMAC — pick by caller.
Connect authenticates three ways. Pick one per caller; do not mix on the same request.
| Mode | Header | Use when |
|---|---|---|
| API key | X-API-KEY: <key> | Machine clients registered as consumers |
| JWT | Authorization: Bearer <token> | People and internal tools (Portal, Try it) |
| HMAC | X-Partner-Signature | Partner inbound webhooks — Sign requests |
API keys
- An operator registers a consumer and copies the key once.
- Assign grants for catalog artifacts (for example
contact-leads). - Call published Experience paths through the gateway.
curl -sS \
-H "X-API-KEY: $CONNECT_API_KEY" \
"https://connect.intronsoft.com/api/v1/leads?limit=10"Ops (/api/v1/ops/**) stays JWT. Keys do not open the portal.
JWT
Authentik issues tokens (authorization code + PKCE for browsers). JWT callers with Developer, Operator, or Admin bypass consumer-grant checks. Machine OAuth is possible; most integrators should use a key.
Try-it on this site uses the public intron-connect client. No client secret is embedded in the docs image.
HMAC
Partners sign the raw body. No Authentik account. See Sign requests.
If this fails
| Symptom | Cause |
|---|---|
| 401 | Missing/expired JWT, or HMAC mismatch |
| 403 | Authenticated but role or grant missing |
| Key works on ping, fails on leads | No contact-leads grant |