Authentication
API keys, where to send them and how to keep them safe.
Provly authenticates every request with a workspace API key. Keys start with pvly_live_ and belong to a workspace, not to a person: anyone holding one can read your workspace's data and use its rate limit.
Sending the key#
Authorization: Bearer pvly_live_…x-api-key: pvly_live_… is accepted too, for tools that cannot set an Authorization header.
Managing keys#
- Create up to 10 active keys per workspace in Settings → API.
- Name keys by where they run (
n8n production,Claude Desktop) so you know which one to revoke. - Revoke a key from the same screen; it stops working within 30 seconds.
- Only a SHA-256 hash is stored. A lost key cannot be recovered, create a new one.
Verify a key#
curl https://provly.co/api/v1/me -H "Authorization: Bearer $PROVLY_API_KEY"Never ship a key in browser or mobile code. Call Provly from your server, an automation tool or an MCP client.
OAuth (MCP connectors)#
Browser-based agents (ChatGPT connectors, claude.ai) sign in with OAuth 2.1 instead of a header: authorization code with PKCE, dynamic client registration and refresh tokens. The consent screen lets the user approve with their Provly account or a pasted API key; either way the connection acts as a workspace key.
| Endpoint | URL |
|---|---|
| Authorization server metadata | https://provly.co/.well-known/oauth-authorization-server |
| Protected resource metadata | https://provly.co/.well-known/oauth-protected-resource |
| Register | POST https://provly.co/api/oauth/register |
| Authorize | https://provly.co/oauth/authorize |
| Token | POST https://provly.co/api/oauth/token |
Access tokens start with pvly_oat_ and last one hour; clients refresh them automatically.
Board and tracker endpoints#
Boards belong to the user who created the key: /boards reads and writes that person's swipe file. Trackers belong to the workspace.
