Sail

Get an API Key

Every request to the Sail API must include an API key in the Authorization header. This page explains how to get your keys,how scopes work, and how to use keys in your requests.

Request API keys

Reach out to the Sail technical team through your dedicated Slack channel to request API keys.

Base URL

All API requests use the following base URL:

https://live.savewithsail.com/api/v1

Authenticate your request

Include your API key as a Bearer token in the Authorization header on every request.

curl -X GET https://live.savewithsail.com/api/v1/users \
  -H "Authorization: Bearer sk_live_..."

Key scopes

Key scopes

Each API key has a fixed set of scopes that control which endpoints it can access. You use the same key on every request, and Sail checks whether that key’s scopes cover the endpoint you’re calling. If not, the API returns 403 insufficient_key_scope.

The Sail team will work with you during implementation to determine the right scopes for your keys. You can request multiple keys with different scopes so that each part of your system only has access to what it needs.

ScopeDescription
expensesRead expense data and create related connections (cards, merchants).
benefit_accountCreate HSA/FSA connections and read account data (balances, activity, contributions).
account_numbersAccess ACH deposit account and routing numbers.
identityAccess personal information (PII) for users and account owners.
ingestPush your own transaction data to a connection for classification.
token_adminCreate and revoke short-lived tokens needed to access PII endpoints.

token_admin is exclusive**

A key with the token_admin scope cannot hold any other scope. This is enforced at key creation. The minting key can create tokens but can’t use them to access data. A separate workload key presents the token to PII endpoints. This ensures that reaching PII always needs two credentials from two deployment contexts.

Scope recommendations by integration path

The scopes you need depend on which integration path you’re following.

Integration pathScopes
Expensesexpenses
Classificationexpenses, ingest
Account connectionbenefit_account, account_numbers, identity

If you’re using PII endpoints (identity, account_numbers), you also need a separate key with the token_admin scope to mint ephemeral user tokens. See Authentication for more on ephemeral tokens.

Next steps