Aura Logo
AuraAPI Docs

Making requests

Authenticate requests, follow pagination and handle errors

Authentication and scopes

For REST requests under /v1, send your partner API key in the Authorization: Bearer <api-key> header. Create and manage keys in Settings → API Keys in the Aura dashboard. Keep keys on your server and out of browser code, screenshots and logs.

An endpoint can require read, write or admin scope. Check the endpoint's reference before issuing a request. A missing required scope returns 403. Test-prefixed keys are read-only and access your organization's production records. Use the staging base URL for pre-production testing.

GraphQL accepts partner keys and Clerk organization JWTs. A Clerk JWT must contain a user and organization claim. Its organization role controls its permissions. REST partner endpoints require a partner key.

REST pagination

List endpoints return pagination.has_more and pagination.next_cursor. Send the returned cursor unchanged as the next request's cursor parameter. Keep filters the same while traversing a result set. Stop when has_more is false. Check each endpoint for its filters and page-size limits.

curl 'https://api.aura-app.ai/v1/leads?limit=50' \
  -H "Authorization: Bearer $AURA_API_KEY"

# Replace the cursor with pagination.next_cursor from the response.
curl 'https://api.aura-app.ai/v1/leads?limit=50&cursor=RETURNED_CURSOR' \
  -H "Authorization: Bearer $AURA_API_KEY"

See List leads for the response shape. GraphQL uses first, after and pageInfo instead, as described in the GraphQL guide.

Errors and retries

REST errors contain success, error, code and requestId. Save the request ID when asking support to investigate. Treat 400 as invalid input, 401 as missing or invalid authentication, 403 as missing permission, and 404 as a resource that cannot be found within your permitted data.

For 429, wait for the number of seconds in Retry-After before retrying. The Overview describes the current limits. For unsafe writes, check whether the endpoint supports idempotency before automatically retrying: Create payment accepts an Idempotency-Key. GraphQL errors also require checking the response's errors array, as described in its guide.

On this page