Skip to main content
Create a user API key, make one request, and confirm that you are connected to the intended tenant.

Before you begin

You need a signed-in Effective workspace account that can open Settings → API Keys. If you do not have workspace access, ask your organization’s Effective administrator. Creating an API key requires a signed-in user session. Having another API key is not a substitute for the browser session.

1. Create a user API key

  1. In your Effective workspace, open Settings → API Keys (workspace path: /settings/api-keys). Stay on the API Keys tab, not Connect Coding Agents.
  2. Select New Key.
  3. In Create New API Key, enter a descriptive Name and choose an Expiration. The default is 90 days. You can also choose 30, 60, or 180 days, or No expiration. Follow your organization’s key-expiration policy.
  4. Create an ordinary user key. If Limit access to specific resources appears, leave it unchecked. Resource-scoped keys do not provide V2 access.
  5. Select Create Key, then copy the key from API Key Created Successfully. Effective shows the full value only once.
Store the key in a secret manager. Do not commit it, put it in a URL, or paste it into a shared chat or agent transcript.
The key inherits your user’s role and selects your tenant. There is no separate V2-specific key type.

2. Make your first request

In an interactive Bash shell, enter the key without leaving the value in your shell history:
For an app or agent, inject EFFECTIVE_API_KEY through its environment or secret store and send Authorization: Bearer <key> with each request. Do not print the key. This REST request does not require an SDK or MCP server.

3. Confirm the tenant

A successful request returns HTTP 200 with an identity like this (illustrative values):
Check that tenantId is the tenant you expect. Treat id and tenantId as opaque strings. name and email can be null. The response uses Cache-Control: no-store.

If the request fails

  • 401 Unauthorized: the key is missing, invalid, expired, revoked, or unsupported. Check that you copied the user key correctly and that it is still active.
  • 403 Forbidden: the credential does not permit this operation. Check that you used an ordinary user key, not a resource-scoped, record-bot, or app-specific credential.
Error responses include a JSON error message. Use the HTTP status for control flow, not the message text. See Authentication and Get current user.

Use with an agent

Find readable documentation and the OpenAPI contract.

Get current user

Review the full endpoint contract.