Overview
The Avero Public API uses Bearer token authentication. Every request must include anAuthorization header with a valid API key.
pf_live_ followed by a 43-character URL-safe random string.
Creating an API key
- Open the Avero desktop app and go to Settings → Developers.
- Click Create API key, enter a name, and select the scopes you need.
- Copy the key — it is shown only once. Store it securely (e.g. in an environment variable or secrets manager).
Scopes
Each key has one or more scopes that limit what it can do.
A request using a key that lacks the required scope returns
403 Forbidden.
Example request
Rate limits
The API is rate-limited to 60 requests per minute per API key. Exceeding the limit returns429 Too Many Requests. The response includes a Retry-After header indicating how many seconds to wait.

