Skip to main content
How Crow authenticates when calling your API.

Auth Types


API Key

Your agent sends a static key in a custom header. OpenAPI spec:
Dashboard config:
  1. Select API Key
  2. Enter header name (X-API-Key)
  3. Enter your key

Bearer Token

Your agent sends a static token in the Authorization header. OpenAPI spec:
Dashboard config:
  1. Select Bearer Token
  2. Enter your token

JWT Forward

Your agent forwards the user’s Crow identity token to your API. This enables user-specific actions like “check my orders” or “cancel my subscription.”
This is not your app’s session JWT. It’s a Crow-scoped identity token your backend mints with CROW_VERIFICATION_SECRET. See Identity Verification.
How it works:
OpenAPI spec:
Dashboard config:
  1. Select JWT Forward
  2. No additional config—token comes from widget user
Your API must verify the token:
JWT Forward only works for authenticated widget users. Anonymous users won’t have a token to forward.

Which to Use?


Troubleshooting


Multi-Subdomain Endpoints

Route API calls to different subdomains with separate credentials