ADR-0015: Version the external API and separate scopes from session roles

PRODUCT SOURCE / 32ecfb2View original ↗

Status: Accepted Date: 2026-10-08

Context

Server integrations need a stable interface without inheriting dashboard sessions or gaining unrestricted access to an organization's customer data.

Decision

Expose resource representations under /api/v1. API keys belong to one organization and carry explicit scopes. Generate 256-bit secrets, display them once, and retain SHA-256 hashes. Every resource query includes organization ownership. Estimate creation requires an idempotency key and calculates from a published revision in a serializable transaction.

Alternatives considered

Session cookies couple integrations to interactive authentication. Unscoped keys grant excessive access. Exposing ORM rows would make database changes break clients.

Consequences

Roles govern key administration; scopes govern API requests. Revocation stops future authentication. Clients retain idempotency keys when retrying writes. Versioned representations and SDK types require coordinated compatibility review.