Layovelle

Authentication

Documentation

The Layovelle REST API uses API keys for authentication. Include your key as a Bearer token in the Authorization header of every request.

Creating an API key

  1. Open the Layovelle app and go to Settings > Developer
  2. Under REST API, click Create Key
  3. Give the key a name (e.g., “CI Pipeline” or “Internal Dashboard”)
  4. Click Create — the key is granted every scope except admin (see Scopes below)
  5. Copy the key immediately — it is only shown once
API keys use the format moda_live_<hex_chars>.

Using your key

Include the key in the Authorization header:
Every request without a valid key returns 401 Unauthorized with WWW-Authenticate: Bearer. Pin Layovelle-Version on every request so your response shapes stay stable across releases — see Versioning.

Scopes

Each API key carries a set of scopes that control what it can access. Audit the table below for the blast radius of a leaked key. All scopes except admin are granted by default when a key is created from Settings — there is no scope picker on that screen. Drive reads (folder list, tree, file list, file metadata) ride canvases:read; only file bytes need files:read. For example, a read-only dashboard integration only exercises canvases:read and designs:read. An automation that generates designs also exercises tasks:write and canvases:write.

Security best practices

Resource ID formats

Every resource has a prefixed wire ID like cvs_01HT9WK8... (canvas), task_01HT9WK8... (task), bk_01HT9WK8... (brand kit). The prefix disambiguates the resource type on sight and prevents accidental cross-resource lookups. One rule for requests, one for responses: Two places are strict and require the typed form:

Revoking a key

Go to Settings > Developer > REST API, find the key, and click Delete. The key stops working immediately. Any requests using the deleted key return 401 Unauthorized.