Auth Types
API Key
Your agent sends a static key in a custom header. OpenAPI spec:- Select API Key
- Enter header name (
X-API-Key) - Enter your key
Bearer Token
Your agent sends a static token in the Authorization header. OpenAPI spec:- Select Bearer Token
- Enter your token
JWT Forward
Your agent forwards the user’s Crow identity token to your API. This enables user-specific actions like “check my orders” or “cancel my subscription.”This is not your app’s session JWT. It’s a Crow-scoped identity token your backend mints with
CROW_VERIFICATION_SECRET. See Identity Verification.- Select JWT Forward
- No additional config—token comes from widget user
JWT Forward only works for authenticated widget users. Anonymous users won’t have a token to forward.
Which to Use?
Troubleshooting
Multi-Subdomain Endpoints
Route API calls to different subdomains with separate credentials
