Authentication
The headers every JaaS call needs, and what a rejected request looks like.
Every call to the JaaS API is authorized before it reaches the service. Endpoints are written relative to the ingestion API base URL Simetrik gives you for your account — the examples call it $SIMETRIK_INGESTION_URL.
The headers
x-api-key: <your api key>
x-skt-workspace: <workspace id>
x-skt-account: <account id>The key and the workspace are validated together, so a valid key presented against the wrong workspace is rejected. The account id identifies the account the workspace belongs to.
Your workspace also has to be enabled for ingestion. That happens once, when Simetrik onboards it; until then no key will get through.
The API key is a workspace-level credential. Keep it server-side — anything holding it can create sources and push records into them.
Which endpoints need what
| Endpoint | Auth headers | Also needs |
|---|---|---|
POST /api/v2/sources | Yes | — |
POST /api/v2/sources/{id}/feed-source | Yes | The source id in the path. |
POST /api/v2/webhooks | Yes | — |
POST /api/v2/webhooks/{webhook_id}/feed-source | No | The webhook_id in the path. |
The inbound webhook endpoint is the exception, and deliberately so: it's called by your systems, and the unguessable webhook_id in the path is what identifies the caller. Treat that id as a secret — anyone holding it can queue files into your source.
When authentication fails
A rejected request never reaches JaaS: it's stopped at the edge and comes back as a 403, with no detail about which check failed. That's deliberate — it doesn't leak whether a workspace, a source or a key exists.
Work through it in this order:
The key itself
Expired, revoked, or copied with a trailing space. Re-issue it if in doubt.
The workspace
It must be the workspace the key was issued for, and it must be enabled for ingestion. On a brand-new workspace, that step may simply not have happened yet.
The account
x-skt-account has to match the account the workspace belongs to.
Response headers
Successful responses are application/json. CORS headers are returned only when your account has an allowed origin configured, which matters if you call the API from a browser rather than from a backend.