Skip to content

docs: use the standard Bearer scheme for API access tokens - #219

Open
ReuDa wants to merge 1 commit into
mainfrom
docs/api-bearer-auth
Open

ReuDa wants to merge 1 commit into
mainfrom
docs/api-bearer-auth

Conversation

@ReuDa

@ReuDa ReuDa commented Sep 24, 2026

Copy link
Copy Markdown
Member

The platform API now accepts access tokens as Authorization: Bearer <token>, the standard format, in addition to the legacy Authorization: accessToken <token> (steadybit/platform#2064). The MCP page already documents Bearer, so this aligns the API page with it.

  • Requests and Responses: documents Bearer as the header format, with a hint that accessToken is still supported and that older on-prem versions accept only the legacy format.
  • Examples: the four curl examples on the page (create token, rate limiting, create experiment, run experiment) use Bearer.

⚠️ Merge only after the platform release that includes steadybit/platform#2064. Until then, Bearer returns 401 on /api/** in SaaS.

BusinessMap: https://steadybitgmbh.kanbanize.com/ctrl_board/2/cards/25243

The platform API accepts Authorization: Bearer <token>. The legacy accessToken format keeps working and is noted as such.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant