Every request carries a personal API key as a bearer token:
curl https://app.splot.health/v1/meals \ -H "Authorization: Bearer $SPLOT_API_KEY"A key acts as you: it reads and changes your own journal, and nothing else.
Create a key
Section titled “Create a key”In the app, open Account → API Keys. Choose a name, a permission and how long the key lasts: 30, 90 or 365 days. The key is shown once, so copy it straight away. Keys start with splot_pat_.
You can have up to 20 active keys. To rotate one, create a replacement, switch to it, then revoke the old key. Revoking takes effect on the next request.
Permissions
Section titled “Permissions”| Permission | Allows |
|---|---|
| Read | Listing and reading meals, searching foods, following your food corrections, and reading your settings, such as daily targets. |
| Read and write | Also creating, changing and deleting meals, saving and deleting your own foods, and changing your settings. |
A request the key’s permission doesn’t cover is answered with 403 and insufficient_scope. Keys can’t manage other keys, connected assistants or your account.
Keeping keys safe
Section titled “Keeping keys safe”- Send keys only in the
Authorizationheader, never in a URL. - Keep them in environment variables or a secret manager, not in code.
- Make sure logs and proxies leave the
Authorizationheader out. - Revoke a key in the app as soon as you no longer need it, or if it may have leaked.
Use this page
Last updated