Skip to content

Authentication

Personal API keys, what each permission allows, and how to keep keys safe.

Every request carries a personal API key as a bearer token:

Terminal window
curl https://app.splot.health/v1/meals \
-H "Authorization: Bearer $SPLOT_API_KEY"

A key acts as you: it reads and changes your own journal, and nothing else.

In the app, open Account → API Keys. Choose a name, a permission and how long the key lasts: 30, 90 or 365 days. The key is shown once, so copy it straight away. Keys start with splot_pat_.

You can have up to 20 active keys. To rotate one, create a replacement, switch to it, then revoke the old key. Revoking takes effect on the next request.

Permission Allows
Read Listing and reading meals, searching foods, following your food corrections, and reading your settings, such as daily targets.
Read and write Also creating, changing and deleting meals, saving and deleting your own foods, and changing your settings.

A request the key’s permission doesn’t cover is answered with 403 and insufficient_scope. Keys can’t manage other keys, connected assistants or your account.

  • Send keys only in the Authorization header, never in a URL.
  • Keep them in environment variables or a secret manager, not in code.
  • Make sure logs and proxies leave the Authorization header out.
  • Revoke a key in the app as soon as you no longer need it, or if it may have leaked.

Last updated