← Docs

API keys and scopes

Each key belongs to one farm and can only do what was selected. Whoever creates a key can only grant scopes they hold themselves. Create and revoke keys in Manage › API keys.

Sending the key

Use either header (the gateway accepts both):

Example
Authorization: Bearer nfk_...
X-Api-Key: nfk_...
Node.js
const res = await fetch("https://api-prod.nextfarm.vn/api/v1/iot/devices?status=offline", {
  headers: { Authorization: `Bearer ${process.env.NEXTFARM_API_KEY}` },
});
const { items } = await res.json();

Scopes

Maps & seasons

ScopeAllows
gis.parcels.viewView parcels and seasons
gis.zones.viewView zones
gis.farmers.viewView farmers
gis.crop-types.viewView crop types
gis.facilities.viewView facilities
gis.layers.viewView map layers

IoT (read-only)

ScopeAllows
iot.devices.viewView devices
iot.telemetry.viewView sensor readings
iot.telemetry.exportExport sensor readings
iot.alerts.viewView alerts

Harvest & traceability

ScopeAllows
farm-harvest.harvest.viewView harvest batches
farm-harvest.harvest.createCreate harvest batches (write)
farm-harvest.qr-codes.viewView QR labels
farm-harvest.trace.viewView traceability
farm-harvest.certification.viewView certificates
farm-harvest.market-prices.viewView market prices

Farm books & tasks

ScopeAllows
office.base.record.viewView book data
office.base.record.manageAdd and edit book rows (write)
office.task.viewView tasks
office.calendar.viewView calendar

Reports

ScopeAllows
report.viewView reports
report.exportExport reports

Safety limits

API keys, webhooks and MCP never control devices — there is no scope for switching or configuring devices, and the gateway blocks every IoT write route for keys.

Error codes

CodeMeaning
401The key is wrong, expired or revoked.
403The key lacks a scope, or the route does not accept API keys (see the detail field).
404Data not found.
422The request data is invalid (the errors field lists each problem).
429Too many requests — read Retry-After, then try again.

Timestamps are returned in UTC (ISO 8601). Lists paginate with page, page_size. JSON request and response bodies use snake_case (e.g. parcel_id) — camelCase keys in a body are ignored.

Full security rules for partners: Security →