Appearance
Getting started
You need a NeodyAI workspace and a person in it who can manage API keys (an owner or admin).
1. Create an API key
- Sign in at app.neody.ai.
- Open Settings → API keys and choose New key.
- Give it a name, a role (
viewer,member,process_owner,financeorapprover) and, optionally, the apps it may use and an expiry. - Copy the key. It starts with
nk_and is shown once. Only a hash is stored, so a lost key can't be recovered; revoke it and create a new one.
Four-eyes workspaces
If the workspace has four-eyes (dual control) on, a new key stays inactive until a second person approves it under Settings → Approvals of changes. Keys can never be owners, admins or risk officers, so a key can't be the second pair of eyes.
2. Make your first call
bash
export NEODY_KEY=nk_your_key_here
curl https://app.neody.ai/api/v1/me \
-H "Authorization: Bearer $NEODY_KEY"The answer tells you who the key acts as, in which workspace, and what it may do:
json
{
"user_id": "key:01J…",
"tenant_id": "01J…",
"email": null,
"kind": "service",
"roles": ["member"],
"apps": ["neody.crm", "neody.work"],
"permissions": ["members.read", "processes.read", "processes.run", "records.read", "records.write", "tasks.work", "usecases.read"],
"account_id": null,
"mfa": false,
"restricted": null
}3. Do something useful
List the apps the workspace can use, then the processes it runs:
bash
curl https://app.neody.ai/api/v1/apps -H "Authorization: Bearer $NEODY_KEY"
curl https://app.neody.ai/api/v1/processes -H "Authorization: Bearer $NEODY_KEY"Start a manual process run with a subject:
bash
curl -X POST https://app.neody.ai/api/v1/processes/<process_id>/start \
-H "Authorization: Bearer $NEODY_KEY" -H "Content-Type: application/json" \
-d '{"subject": {"type": "none", "label": "Order 42"}}'Base URL
| Environment | Base URL |
|---|---|
| Production | https://app.neody.ai/api |
All paths in this documentation start with /v1. Requests and responses are JSON (Content-Type: application/json), except uploads (multipart/form-data).
Next
- Authentication — keys, sessions and how a call is authorised.
- Permissions — what each role may do.
- API reference — every endpoint.