Authentication
Access tokens
The Polaris API authenticates using Bearer tokens. Every request must include the token in the Authorization header:
curl https://polaris.revlv.com/v1/devices \
-H "Authorization: Bearer {token}" \
Each token belongs to a workspace. Requests return data for that workspace and any workspaces nested under it. Tokens are prefixed with polaris_ and do not expire by default.
List the workspaces a token can reach with GET /v1/workspaces, and scope any read to a single one with the workspaceId query parameter.
Generate a token in the Polaris dashboard under Manage → API keys.
Keep your token secret. If you suspect it has been compromised, revoke it immediately from the dashboard and issue a new one.
Headers
| Header | Required | Description |
|---|---|---|
Authorization | Yes | Bearer {token} |
Error responses
| Status | Meaning |
|---|---|
401 Unauthorized | Token missing, invalid, or expired |
403 Forbidden | Token valid but no access to the resource |
429 Too Many Requests | Rate limit exceeded. See the Retry-After header |