Zernio
Zernio
API Reference

API Keys

List keysGETCreate keyPOSTDelete keyDELETEVerify credentialGET
Dashboard
llms.txtOpenAPI
OverviewPlatformsAPI ReferenceResources
API Keys

Verify credential

Checks whether the bearer credential on this request is valid, without reading any data. Accepts an API key or an OAuth access token. Intended for clients that must validate a credential before use (for example an MCP server verifying an incoming token) so they do not have to call a data endpoint to do it.


GET
/v1/auth/verify

Authorization

bearerAuth
AuthorizationBearer <token>

API key authentication: send your Zernio API key in the Authorization header, prefixed with Bearer.

In: header

Response Body

application/json

application/json

{  "valid": true,  "userId": "6507a1b2c3d4e5f6a7b8c9d0",  "name": "Ada Lovelace",  "email": "ada@example.com",  "authType": "oauth",  "scope": "posts:read posts:write accounts:read"}
Was this page helpful?

Delete key

Permanently revokes and deletes an API key.

Create webhook

Create a new webhook configuration. Maximum 50 webhooks per user. `name`, `url` and `events` are required. `url` must be a valid URL and `events` must contain at least one event. Whitespace is trimmed from `url` before validation. Webhooks are auto-disabled only once the endpoint has had no successful delivery for 3 days AND has either reached 20 consecutive terminal failures (each one an event that exhausted the full retry ladder) or been failing continuously for 3 days. The owner is emailed; re-enable it with `isActive: true`. A restricted (zrk_) API key can only subscribe to events whose resource group the key holds; an event outside the key's groups is rejected with 403, so a restricted key can never create a subscription broader than itself. `disabledResourceGroups` restricts the subscription itself, independently of which key or session later reads it. Events in a disabled group are dropped before delivery to this endpoint, on live delivery and on every replay path (test fire, redelivery, dead-letter requeue), even if they are listed in `events`. Omit it to receive everything in `events`, which is how existing subscriptions behave. A restricted key's own disabled groups are always unioned in.