Orvelt
API reference

Authentication

Authenticate Business API requests with an organization API key in the x-api-key header.

Every public Business API operation requires an organization API key in the x-api-key header. A key can access every project in its organization, subject to its operation permissions. Create the key in Orvelt Business → Settings → API Keys.

Keys begin with ov_. Store the full value in a server-side secret manager. Orvelt shows the secret once when you create it.

SDK authentication

Configure the shared client

The SDK adds the header for each operation after you configure it:

import { orvelt } from '@orvelt/business';

orvelt({
  apiKey: process.env.ORVELT_BUSINESS_API_KEY!,
});

REST authentication

Send the API-key header

Send the same key explicitly with cURL. The SDK tab shows the equivalent generated operation:

import { knowledgeBase } from '@orvelt/business';

const result = await knowledgeBase.get();
if (result.error) throw new Error(result.error.message);
curl --request GET \\
  --url "$ORVELT_API_BASE_URL/kb" \\
  --header "x-api-key: $ORVELT_BUSINESS_API_KEY"

Handle authentication failures

A missing or invalid key returns 401 Unauthorized. A valid key can still receive 403 Forbidden when it lacks the permission required by an operation.

Do not expose keys in browser code

API keys grant access to business data. Call the Business API from your server, worker, or trusted internal tool. Proxy browser requests through an authenticated server endpoint instead.

Base URL

Choose production or an override

Use https://api.orvelt.com/v1 in production. The SDK and the cURL examples in these docs use the same path prefix. Set ORVELT_API_BASE_URL to a staging or proxy URL without a trailing slash when you need a different environment.