Skip to main content
Every endpoint except GET /health and GET /docs requires an API key, sent as a bearer token:
Keys start with pf_ followed by the key’s environment (for example pf_live_). The full key is shown exactly once, when you create it, and can’t be retrieved again. Store it in a secrets manager and only use it from your servers. Never put it in browser or mobile code.

Key types

An agency key acts as your agency’s API integration, not as any one person.
  • Who can create one: agency owners, on the API Keys tab of the agency settings (/agency/api-keys).
  • Availability: Paraform enables API access per agency. If you don’t see the API Keys tab, ask your Paraform contact.
  • Scopes: chosen when you create the key (see Scopes). The talent_network:* scopes are offered only when your agency has Talent Network access.
  • Limits: up to 50 active keys per agency. A key can have an optional expiry date and can be revoked at any time.

Scopes

Each endpoint requires one or more scopes, listed on its reference page. A key can call an endpoint only if it holds every scope the endpoint requires. Agency keys also carry talent_network:read automatically, whatever scopes you picked, so GET /identity lists it. Personal keys can’t hold agency scopes, so agency-only endpoints, such as the Talent Network endpoints, answer 403 for them.

Authentication errors

See Errors for the full error format.

Check your key

GET /identity returns who your key acts as (principal is agency or recruiter) and its effective scopes. Use it as a connectivity and configuration check before anything else.