GET /health and GET /docs requires an API key, sent as a bearer token:
pf_ followed by the key’s environment (for example pf_live_). The full key is shown exactly once, when you create it, and can’t be retrieved again. Store it in a secrets manager and only use it from your servers. Never put it in browser or mobile code.
Key types
- Agency keys
- Personal keys
An agency key acts as your agency’s API integration, not as any one person.
- Who can create one: agency owners, on the API Keys tab of the agency settings (
/agency/api-keys). - Availability: Paraform enables API access per agency. If you don’t see the API Keys tab, ask your Paraform contact.
- Scopes: chosen when you create the key (see Scopes). The
talent_network:*scopes are offered only when your agency has Talent Network access. - Limits: up to 50 active keys per agency. A key can have an optional expiry date and can be revoked at any time.
Scopes
Each endpoint requires one or more scopes, listed on its reference page. A key can call an endpoint only if it holds every scope the endpoint requires.
Agency keys also carry
talent_network:read automatically, whatever scopes you picked, so GET /identity lists it. Personal keys can’t hold agency scopes, so agency-only endpoints, such as the Talent Network endpoints, answer 403 for them.
Authentication errors
See Errors for the full error format.
Check your key
GET /identity returns who your key acts as (principal is agency or recruiter) and its effective scopes. Use it as a connectivity and configuration check before anything else.