# Authentication and Conventions

Source: https://help.zira.us/developers/api-reference/authentication-and-conventions
Summary: Understand the base URL, API key authentication model, and common request patterns used by the Zira SDK HTTP endpoints.
Updated: 2026-03-26

This page describes the common rules used by the public Zira SDK HTTP endpoints.

## Base URL

```text
https://api.zira.us/public
```

## Authentication

All public HTTP endpoints in this SDK use API-key authentication.

Required header:

```http
x-api-key: <your-api-key>
```

Notes:

- No login access token is required for these documented SDK endpoints.
- Some handlers internally exchange the API key for an authorization token when invoking other internal services.

## Common integration expectations

- Treat these endpoints as command or integration endpoints, not just thin CRUD wrappers.
- Some endpoints trigger side effects such as notifications or downstream processing.
- Validation rules can be strict, especially around time formats and metric mapping.

## Current coverage

The API exposes 26 HTTP-routed endpoints. Fourteen of them have a full reference page — request
contract, response example and field tables — and those are the ones listed in the sidebar. The rest
are either legacy variants of a documented endpoint or exist only for Zira's own devices and apps.

There are also 9 handlers with no HTTP route at all, which cannot be called from an integration.

## Related pages

- [Files, Uploads, and Export](/developers/api-reference/files-uploads-and-export)
- [Readings API](/developers/api-reference/readings-api)
- [Tasks API](/developers/api-reference/tasks-api)
- [Data Sources and Device APIs](/developers/api-reference/data-sources-and-devices)
