API reference

Authentication

Use organization API keys or user-scoped OAuth tokens.

Every Homie API request must include Authorization: Bearer <credential>. The API accepts two credential types:

  • An organization API key beginning with homie_sk_. Use this for organization-wide searches and lookups.
  • A user-scoped MCP OAuth access token. Use this when an endpoint needs the signed-in user's own network.

The List connections and List second-degree connections endpoints require a user-scoped token. The scope=me option on Search warm paths does too. An organization API key receives 403 forbidden_scope for those requests.

Generate a key

  1. Sign in to Homie as an admin.
  2. Go to Settings > Integrations > Developer.
  3. In the Homie API card, click Manage keys.
  4. Click Generate key and give it a name (e.g. Production, Local dev).
  5. Copy the full key from the one-time reveal modal. You won't see it again.

Keys start with homie_sk_. Treat them like passwords; anyone with the key can read your organization's data.

Send a request

KEY=homie_sk_...curl -H "Authorization: Bearer $KEY" \https://app.usehomie.com/api/v1/search/people?q=alex
const res = await fetch("https://app.usehomie.com/api/v1/search/people?q=alex", {headers: { Authorization: `Bearer ${process.env.HOMIE_API_KEY}` },});const { data } = await res.json();
import os, requestsres = requests.get("https://app.usehomie.com/api/v1/search/people",params={"q": "alex"},headers={"Authorization": f"Bearer {os.environ['HOMIE_API_KEY']}"},)data = res.json()["data"]

Revoke a key

In the same dialog, click the trash icon next to a key to revoke it. Revoked keys stop working immediately. There is no grace period.

Storage

Keys are stored as a SHA-256 hash. Only the prefix is retained for identification. If you lose a key, you must generate a new one.

Permissions

Every organization API key currently has read access to your organization's network. Per-key scopes are on the roadmap.

MCP access tokens carry mcp:read and, when approved, mcp:write. The REST endpoints documented here are read-only. See the MCP OAuth flow for token issuance and scopes.

On this page