Header
Authorization
Authorization: Bearer $HR_API_KEY
Server-only rule
- Use the key from backend code only.
- Return product-shaped responses to the browser.
- Proxy file previews and downloads through authenticated product routes.
- Do not forward caller-controlled org, member, Workspace, or harness IDs without server-side validation.
