Skip to content
Authentication

Authentication

The Dango public API is organization-scoped and authenticated with API keys. The public API base URL is https://api.dangofish.com.

API keys

An organization admin generates API keys (name + expiration) from the organization settings, under the API Keys page. Key management is admin-only.

An API key is prefixed with dk_org_. The plaintext key is shown only once, at creation time: copy it immediately and store it securely. After creation, only the key’s SHA-256 hash is stored; Dango can never display the plaintext value again. If a key is lost, revoke it and issue a new one.

Making authenticated calls

Every request must carry the key in the Authorization header as a bearer token:

Authorization: Bearer dk_org_...

How a key is verified

Each incoming request passes through the AuthInterceptor, which:

  1. Rejects any key that is not prefixed with dk_org_, before any database access.
  2. Computes the key’s SHA-256 hash and resolves the corresponding organization and its scopes. A key that is inactive or expired is rejected.
  3. Injects the resolved organization into the request context.

Authorization model

Authorization is determined by organization membership: a request may act on a project only if that project belongs to the same organization as the API key. Access is never granted per individual user: the key represents the organization, not a person.

A project created through the API belongs to the organization and is visible to its members on the web app.