API
An API with the same ceiling as your user.
ALL WR exposes a versioned JSON API under /api/v1. It exists so you can connect the file to what you already use, not so a key can bypass the permissions of the person who created it.
Three rules that do not move
- A key cannot grant more access than the person who creates it already has. Someone else’s key answers as if it did not exist.
- Every external route requires that key. Knowing an identifier is not a shortcut.
- Outbound webhooks are signed with HMAC-SHA256. Reject the ones that do not match.
AI assistants
The MCP server is at https://www.allwr.io/mcp. Each person signs in with their own account: it is not a shared team key. How to connect each assistant is documented on the MCP page of this site.
Ask for access
We do not publish an endpoint catalogue here that would go stale the day a route changes. If you are integrating, write to hola@allwr.io, say which system you want to connect, and we will point you at the key and the real scope.