Authentication
The Dango public API is organization-scoped and authenticated with API keys. The public API base URL is https://api.dangofish.com.
API keys
An organization admin generates API keys (name + expiration) from the organization settings, under the API Keys page. Key management is admin-only.
An API key is prefixed with dk_org_. The plaintext key is shown only once, at creation time: copy it immediately and store it securely. After creation, only the key’s SHA-256 hash is stored; Dango can never display the plaintext value again. If a key is lost, revoke it and issue a new one.
Making authenticated calls
Every request must carry the key in the Authorization header as a bearer token:
Authorization: Bearer dk_org_...How a key is verified
Each incoming request passes through the AuthInterceptor, which:
- Rejects any key that is not prefixed with
dk_org_, before any database access. - Computes the key’s SHA-256 hash and resolves the corresponding organization and its scopes. A key that is inactive or expired is rejected.
- Injects the resolved organization into the request context.
Authorization model
Authorization is determined by organization membership: a request may act on a project only if that project belongs to the same organization as the API key. Access is never granted per individual user: the key represents the organization, not a person.
A project created through the API belongs to the organization and is visible to its members on the web app.