Skip to main content
AvraAPI provider and UPG server APIs authenticate a request using a project Client ID, Client Secret, and environment selector.

Required headers

When X-ENV is omitted, the API treats the request as Development. The credential is still checked against that environment boundary.

Store secrets safely

Generate and rotate credentials

The dashboard shows a full Client Secret only when it is generated or rotated. If it is lost or exposed, rotate it immediately and update every affected server deployment.
Rotating a credential invalidates the previous secret. Plan a controlled deployment so your running application receives the replacement before the old credential is removed from use.

Authentication failures

Missing, inactive, mismatched, or invalid credentials produce an unauthorized error. Paused projects return project_paused and should be handled as an operational state rather than retried continuously.
See API key safety for incident-response guidance.
Last modified on October 1, 2026