Data API
Authentication
AimRack authenticates Data API requests with a scoped, optionally expiring API key — the same key that unlocks the AimRack API.
Create a key in , then send it on every request as a bearer token: Authorization: Bearer <api-key>.
curl '<your-host>/item?limit=1' \
-H "Authorization: Bearer <api-key>"The example uses your configured REST origin. When calling PostgREST directly, send carbon-key: crbn_… against /rest/v1/<table> instead.
Creating a key
Choosing New API Key opens a dialog with three fields:
Permissions
Each checkbox grants one action on one module. The action maps to the HTTP method of the request:
GETPOSTPATCHDELETEReading from /item, for example, needs Parts → View. A request for an action the key does not hold returns 403. Some modules omit actions they do not support (Accounting has no Delete, shown as --).
Expiration & errors
If a key is past its Expires At date, requests fail with 401 before anything runs. Other authentication failures:
401403429