Skip to main content

Overview

The Avero Public API uses Bearer token authentication. Every request must include an Authorization header with a valid API key.
API keys begin with pf_live_ followed by a 43-character URL-safe random string.

Creating an API key

  1. Open the Avero desktop app and go to Settings → Developers.
  2. Click Create API key, enter a name, and select the scopes you need.
  3. Copy the key — it is shown only once. Store it securely (e.g. in an environment variable or secrets manager).
Never embed an API key in client-side code or commit it to version control.

Scopes

Each key has one or more scopes that limit what it can do. A request using a key that lacks the required scope returns 403 Forbidden.

Example request

Rate limits

The API is rate-limited to 60 requests per minute per API key. Exceeding the limit returns 429 Too Many Requests. The response includes a Retry-After header indicating how many seconds to wait.

Error responses