Skip to main content
Everything the dashboard does to proposals and experiments goes through https://api.trevosdk.com/v1. A workspace API key lets a script, a CI job, or an agent do the same: list what Trevo proposed, approve or dismiss, send revision instructions, ask for a fresh batch, start and end experiments.

Keys

Make one under Settings → API access. A key:
  • opens one workspace — no workspace header needed, and one that disagrees is refused;
  • reads everything in it, and writes only what its scopes allow — proposals.review, experiments.manage, experiments.decide, funnels.manage, each a permission the routes already check for people;
  • acts as the person who made it in the audit log and in what Trevo says it did;
  • is shown once, stored hashed, and revocable from the same page.
A key cannot manage keys, billing, members, or the organisation. SDK keys (tsk_live_, tsk_secret_) are your site’s, and are refused on these routes. Every write a key makes is recorded in the audit trail as that key, beside the person it acts as — the dashboard’s trail and the CSV export both name it, and GET /v1/audit?actorApiKeyId=… filters to one key.

The CLI

Every command takes --json and prints the API response verbatim. Exit codes: 0 ok, 1 the API refused (the reason and its code are on stderr), 2 usage, 3 auth — so a script can tell a revoked key from a proposal that was not approvable. Installation and CI setup: CLI. Reading is always allowed; the Scope column is the permission a key needs for the write.

Keys and identity

Proposals

Generation

Experiments

Funnels

Reference

The OpenAPI description of these routes is at /reference/openapi.json. It is generated from the schemas the API parses, so it describes what the routes actually accept and return. Refusals carry a code worth branching on: