Authentication
Use organization API keys or user-scoped OAuth tokens.
Every Homie API request must include Authorization: Bearer <credential>. The API accepts two credential types:
- An organization API key beginning with
homie_sk_. Use this for organization-wide searches and lookups. - A user-scoped MCP OAuth access token. Use this when an endpoint needs the signed-in user's own network.
The List connections and List second-degree connections endpoints require a user-scoped token. The scope=me option on Search warm paths does too. An organization API key receives 403 forbidden_scope for those requests.
Generate a key
- Sign in to Homie as an admin.
- Go to Settings > Integrations > Developer.
- In the Homie API card, click Manage keys.
- Click Generate key and give it a name (e.g.
Production,Local dev). - Copy the full key from the one-time reveal modal. You won't see it again.
Keys start with homie_sk_. Treat them like passwords; anyone with the key can read your organization's data.
Send a request
KEY=homie_sk_...curl -H "Authorization: Bearer $KEY" \https://app.usehomie.com/api/v1/search/people?q=alexconst res = await fetch("https://app.usehomie.com/api/v1/search/people?q=alex", {headers: { Authorization: `Bearer ${process.env.HOMIE_API_KEY}` },});const { data } = await res.json();import os, requestsres = requests.get("https://app.usehomie.com/api/v1/search/people",params={"q": "alex"},headers={"Authorization": f"Bearer {os.environ['HOMIE_API_KEY']}"},)data = res.json()["data"]Revoke a key
In the same dialog, click the trash icon next to a key to revoke it. Revoked keys stop working immediately. There is no grace period.
Storage
Keys are stored as a SHA-256 hash. Only the prefix is retained for identification. If you lose a key, you must generate a new one.
Permissions
Every organization API key currently has read access to your organization's network. Per-key scopes are on the roadmap.
MCP access tokens carry mcp:read and, when approved, mcp:write. The REST endpoints documented here are read-only. See the MCP OAuth flow for token issuance and scopes.