Authentication
API keys, scopes, environments and rotation.
Send your key in the Authorization header on every request:
Authorization: Bearer dwn_live_k2x9…Keys belong to a workspace
A key created while a workspace is active acts for that workspace and only sees its rooms and meetings. A key created on a personal account acts for that account. Only a workspace's owners, admins, or a role with Manage API keys and webhooks can create keys for it, and a key stops working if the person who created it loses that right.
Scopes
| Scope | Allows |
|---|---|
rooms:read | List and retrieve rooms |
rooms:write | Create, update, lock and delete rooms |
meetings:read | List and retrieve scheduled meetings |
meetings:write | Schedule and cancel meetings |
tokens:create | Create join links and media tokens |
participants:read | See who is in a meeting |
participants:write | Mute and remove people, end meetings |
polls:read | Read polls and their results |
polls:write | Create, close and delete polls |
breakouts:read | See breakout rooms and who is in them |
breakouts:write | Start, change, announce to and end breakout rooms |
recordings:read | List recordings and fetch their parts |
recordings:write | Delete recordings |
webhooks:manage | Manage webhook endpoints |
Give each integration the narrowest set it needs. A key that only sends people into existing rooms needs just rooms:read and tokens:create (the Join only preset).
Live and test keys
Keys start with dwn_live_ or dwn_test_. Both work against the same workspace; the label helps you keep staging and production credentials apart. Use separate keys per environment so you can revoke one without touching the other.
Rotating a key
- Create a new key with the same scopes.
- Deploy it to your servers.
- Watch last used on the old key until it stops changing, then revoke it.
Keys can also be created with an expiry (30, 90 or 365 days).
Checking a key
curl https://deewan.io/api/v1/me -H "Authorization: Bearer $DEEWAN_API_KEY"