API/Authentication

Authentication

Authenticate every node operation with an API key in the Authorization header.

Authorization: Bearer <your-api-key>

Create an API key

In the dashboard, open Developers, then API Keys. Create a key for your integration and select the permissions it needs. Save the full key when it is shown; it cannot be retrieved later.

Send authenticated requests

Replace YOUR_API_KEY with your API key.

curl https://api.nodana.io/v1/nodes \
  -H "Authorization: Bearer YOUR_API_KEY"

The API reads the Authorization header. The CLI reads NODANA_API_KEY and sends it in that header; direct HTTP requests do not require this environment variable.

To inspect the current key's ID, account ID, and scopes, call GET /api-key with that Bearer header. This endpoint does not reveal the secret or create a new key.

Permissions

PermissionScopeOperations
Readnodes:readList nodes, read node details, and check available updates
Writenodes:writeCreate, rename, start, stop, restart, update, and delete nodes

Read is required for every key and is selected automatically. Enable Write if an integration also needs to change nodes. Keys belong to one account. The API uses the key to determine your account; you do not need to send an account ID. The key must include the required scope. Missing, invalid, disabled, or revoked keys and insufficient scopes return 401 Unauthorized. Nodes belonging to another account return 404 Not Found.

Keep keys private

Use keys from your backend or trusted scripts. Store them in secret storage, keep them out of browser code and source control, and revoke or replace them if exposed.

A Nodana API key authenticates node operations. Your node's Phoenixd password is a separate credential for its payment API.

On this page