Meta
Check the service and inspect your own key.
Two endpoints answer the first questions of any integration: is the API up, and what can this key do? Call them before you debug anything else. The answer to “why is this call a 403” is almost always in /me.
GET/pingno authentication
Needs no key. It confirms the API is reachable and reports the version it serves, so it works as a health check for your monitoring.
curl https://tahoe.workonward.com/api/partner/v1/ping{
"object": "ping",
"ok": true,
"api_version": "2026-09-09"
}GET/meany valid key
Works with any valid key, whatever its scopes. It describes the key you sent: what it may read, which workspaces it reaches, whether it must name one on every call, and its limits and usage today.
curl https://tahoe.workonward.com/api/partner/v1/me \
-H "Authorization: Bearer $TAHOE_API_KEY"{
"object": "credential",
"id": "pk_9tRc4mQx7Lb2",
"name": "Acme HRIS sync",
"environment": "live",
"scopes": ["applications:read", "contact:read", "jobs:read", "workspaces:read"],
"scope_descriptions": {
"applications:read": "Applications, their stage and status, and match scores.",
"contact:read": "Work and personal email addresses your workspace has already revealed.",
"jobs:read": "Job postings, their content, application forms and pipeline stages.",
"workspaces:read": "Workspace name and creation date."
},
"workspace_scope": "list",
"workspace_ids": ["wsp_4Kd8sPm2Qx7L"],
"workspace_id_required": false,
"rate_limits": {
"general_per_minute": 600,
"expensive_per_minute": 60,
"download_per_minute": 30,
"personal_data_reads_per_day": 5000,
"personal_data_reads_used_today": 128,
"max_page_size": 100,
"max_result_window": 10000
},
"created_at": "2026-09-09T10:14:22.510Z",
"expires_at": "2026-12-08T10:14:22.510Z",
"api_version": "2026-09-09"
}| Field | Meaning |
|---|---|
id | The key handle. Safe to log, and the ID to quote when you contact us. |
name | The name the key was given when it was created. |
environment | live or test. Both read the same data; the prefix only tells them apart in your logs. |
scopes | Exactly what the key may read and change. |
scope_descriptions | A one-line description of each scope. |
workspace_scope | list: the key reaches the workspaces in workspace_ids. all: a cross-workspace key. |
workspace_ids | The workspace handles a list key can reach. |
workspace_id_required | true for a cross-workspace key: every request must pass ?workspace_id=wsp_..., or it fails with 400 workspace_id_required. A list key that covers more than one workspace must pass it too. |
rate_limits | Your request limits per minute, the daily personal-data budget and how much of it you have used today, the largest page size and the deepest you can page. Rate limits and quotas |
expires_at | When the key stops working, or null if it never expires. |
api_version | The same date the Tahoe-Api-Version header carries. |
The OpenAPI document
A machine-readable OpenAPI document is served under the base URL. It is generated from the running service rather than written by hand, so if it and these pages ever disagree on a parameter name or a response shape, the OpenAPI document is right.
curl https://tahoe.workonward.com/api/partner/v1/openapi.json -o tahoe-openapi.jsonRelated
- API keys and scopes: what each scope grants.
- Errors: every error code and whether to retry.
- Workspaces and users: the workspaces a key can reach, by name.