Authenticate API requests
API operations accept the credential named in their reference. Team API keys serve integrations; participant operations require an access token identifying a Slack member.
You need: a credential for the environment and workspace you are accessing.
Choose a credential
Section titled “Choose a credential”| Operation | Credential |
|---|---|
| Rotation reads, configuration and direct duty operations | Team API key with the required scope and rotation access |
| Cover and swap request lists, details and swap candidates | Team API key with read:oncall |
| Cover and swap participant previews and responses | Round Robin access token for a signed-in Slack member |
| Availability impact preview | Round Robin access token for a signed-in Slack member |
A team API key cannot accept cover or a swap on someone’s behalf. A participant access token does not replace a team API key on operations that require the key.
Send a bearer token
Section titled “Send a bearer token”Send the credential in the Authorization header using the Bearer scheme. Keep the token out of URLs, source control and logs.
Create a team key under Settings → API keys. See Creating and managing API keys. Use a separate key for each integration and restrict its scopes and rotations to the work it performs.
Development keys start with rr_dev_; production keys start with rr_live_. Use the matching environment. If a key is lost, create a replacement.
Participant operations authenticate through Auth0. Use a Round Robin access token for the signed-in Slack member; Slack Web API tokens such as xoxp or xoxb are not accepted. Do not copy session credentials from another person’s browser. See Participant duty operations for the preview and response sequence.
Resolve an authentication refusal
Section titled “Resolve an authentication refusal”API-key code |
What to do |
|---|---|
missing_credential |
Send a team API key in the bearer header for this operation. |
unknown |
Check the token and environment. Replace a revoked key. |
disabled |
Ask a workspace admin to review the key and its owner. |
expired_secret |
Replace the outgoing secret with the current one. |
For a participant operation, confirm that the token identifies a Slack member with access to the workspace. Review the operation’s required credential before changing scopes.
Next steps
Section titled “Next steps”- Creating and managing API keys: create or replace an integration credential.
- Scopes and access: restrict what a key can do.
- Participant duty operations: preview and respond as a member.
