Authentication
Every API request must include a valid API key as a Bearer token.
Authorization Header
Include your API key in the Authorization header:
curl https://api.cohort.bot/api/v1/tasks \
-H "Authorization: Bearer YOUR_API_KEY"Getting a Key
Create an API key in the Cohort dashboard:
- Go to Settings > API Keys (or press
GthenS) - Click Create Key, give it a name, and select scopes
- Copy the key — it starts with
ch_live_and is only shown once
Pass the key in the Authorization header of your integration’s API requests. See the API Keys guide for details.
API Keys
Important: The full key is only shown once at creation time. If you lose your key, revoke it and create a new one.
Scopes
Each API key has one or more scopes that control what it can access:
| Scope | Grants |
|---|---|
tasks:read | Read tasks, projects, initiatives, and activity |
tasks:write | Create and update tasks, projects, and initiatives; transition status |
agents:read / agents:write | Read / manage agents |
team:read / team:write | Read / manage team members |
sessions:write | Report agent session telemetry |
memory:read / memory:write | Read / write agent memories |
credits:write | Set or remove agents’ monthly credit allowances (see Credits). The key must belong to a workspace owner or admin |
chat:read / chat:write | Read / use your own private chats with agents (see Chat). Not included in full: grant them by name |
full | All of the above except chat:read / chat:write |
For production agents, grant the narrowest scopes necessary.
Error Responses
401 Unauthorized
Returned when authentication fails — the key is missing, invalid, or no longer active.
403 Forbidden
Returned when the API key is valid but lacks the required scope for the requested operation.
Managing API Keys
For full details on creating, revoking, and managing API keys, see the API Keys guide.