ProvlyDocs

Search docs

Guides and API endpoints

DocsGet startedAuthentication

Authentication

API keys, where to send them and how to keep them safe.

Provly authenticates every request with a workspace API key. Keys start with pvly_live_ and belong to a workspace, not to a person: anyone holding one can read your workspace's data and use its rate limit.

Sending the key#

Header
Authorization: Bearer pvly_live_…

x-api-key: pvly_live_… is accepted too, for tools that cannot set an Authorization header.

Managing keys#

  • Create up to 10 active keys per workspace in Settings → API.
  • Name keys by where they run (n8n production, Claude Desktop) so you know which one to revoke.
  • Revoke a key from the same screen; it stops working within 30 seconds.
  • Only a SHA-256 hash is stored. A lost key cannot be recovered, create a new one.

Verify a key#

bash
curl https://provly.co/api/v1/me -H "Authorization: Bearer $PROVLY_API_KEY"

Never ship a key in browser or mobile code. Call Provly from your server, an automation tool or an MCP client.

OAuth (MCP connectors)#

Browser-based agents (ChatGPT connectors, claude.ai) sign in with OAuth 2.1 instead of a header: authorization code with PKCE, dynamic client registration and refresh tokens. The consent screen lets the user approve with their Provly account or a pasted API key; either way the connection acts as a workspace key.

EndpointURL
Authorization server metadatahttps://provly.co/.well-known/oauth-authorization-server
Protected resource metadatahttps://provly.co/.well-known/oauth-protected-resource
RegisterPOST https://provly.co/api/oauth/register
Authorizehttps://provly.co/oauth/authorize
TokenPOST https://provly.co/api/oauth/token

Access tokens start with pvly_oat_ and last one hour; clients refresh them automatically.

Board and tracker endpoints#

Boards belong to the user who created the key: /boards reads and writes that person's swipe file. Trackers belong to the workspace.