API Key Authentication

API keys provide stateless authentication for scripts, CI/CD pipelines, and external integrations. Keys are passed via the X-API-Key HTTP header.

Key format: osprey_<64-hex-chars> (e.g., osprey_a1b2c3d4...). The 64-character hex suffix is a cryptographically random 32-byte value.

Security model:

Usage:

GET /api/v1/devices?area_id=... HTTP/1.1
X-API-Key: osprey_a1b2c3d4e5f6...