API / Space guide

Build with the API

Space is in development. These guides describe the current development version and the intended workflow. Public sign-ups and hosted agent connections are not available yet.

Build your own views and tools on the documents, tasks and memory in a Space.

The Space REST API is the same API the workspace uses. With a personal API key, your own app, script or front-end can read a Space and, if you allow it, change it.

What an API key can do

A key acts as the person who created it, in one Space only. It never has more access than you have in that Space.

  • Read-only keys can read documents, tasks, memory, projects, folders and databases, search, recall context and export the Space.
  • Read and write keys can also create, edit and delete those items. Changes made with a key are saved as yours.
  • No key can manage agents, API keys, members, invitations, billing, restores, webhooks or visibility.
  • API keys do not work on the MCP endpoint. Agents connect through an agent connection instead.

Create a key

Open Settings → API keys in the Space you want to use. Name the key after the app that will use it, choose its access, and choose when it expires: after 30 days, 90 days, a year, or never. If you can only view a Space, your keys are read-only.

The full key, which starts with spk_, is shown once, right after you create it. Copy it then: Space keeps only a short prefix to help you recognize it in your list. You can have up to 25 active keys in each Space.

Find your API URL

Requests go to your Space API URL, not to this website. It is the address of your Space’s MCP endpoint without /mcp/: if the Agents page shows https://<api-host>/mcp/, your API URL is https://<api-host>. Settings → API keys also shows it, with your Space ID.

The API reference lists exactly the routes an API key can call, with every request and response field. The API host also serves the same machine-readable OpenAPI schema at /openapi.json.

Make your first request

Send the key as a bearer token in the Authorization header. Keep it in an environment variable rather than in your code.

export SPACE_API_URL="https://<api-host>"
export SPACE_API_KEY="spk_..."

curl -H "Authorization: Bearer $SPACE_API_KEY" \
  "$SPACE_API_URL/v1/workspace"

The response describes the key’s Space: its id, name, your role and the tasks_collection_id. Use the id in every other path. To list your tasks:

export SPACE_ID="<id from the response>"

curl -H "Authorization: Bearer $SPACE_API_KEY" \
  "$SPACE_API_URL/v1/spaces/$SPACE_ID/resources?kind=task"

With a read and write key, create a task with a new command_id for each change, so a retried request is saved only once. Updates send the item’s resource_id and its current revision as expected_revision.

curl -X POST -H "Authorization: Bearer $SPACE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"command_id": "'"$(uuidgen)"'", "expected_revision": 0,
       "kind": "task", "title": "Draft the launch post"}' \
  "$SPACE_API_URL/v1/spaces/$SPACE_ID/resources"

Endpoints you will use most

  • GET /v1/workspace: the key’s Space.
  • GET /v1/spaces/{space_id}/resources?kind=document or ?kind=task: list documents or tasks.
  • GET /v1/spaces/{space_id}/resources/{resource_id}: read one document or task.
  • POST /v1/spaces/{space_id}/resources: create or update a document or task.
  • POST /v1/spaces/{space_id}/search: search the Space, with a body such as {"query": "launch"}.
  • POST /v1/spaces/{space_id}/context: recall memory for a question, with a body such as {"query": "release checklist"}.
  • GET /v1/spaces/{space_id}/memories: list saved memories.
  • GET /v1/spaces/{space_id}/map: the Space’s sections, projects, folders and databases.
  • POST /v1/spaces/{space_id}/export: export the Space’s content.

The API reference covers the remaining routes, and API concepts explains paging, retries and error responses.

Keep your key safe

The API accepts requests from any website and uses no cookies, so a browser front-end can call it directly. But a key embedded in a public website is visible to anyone who loads the page, and they can use it as you.

  • Keep keys on a server you control, or in an app that runs only on your own computer.
  • Prefer read-only keys, and give each app its own key with an expiry.
  • If a key leaks, revoke it in Settings → API keys at once. Revoking takes effect on the key’s next request.

Read Privacy & data for how Space stores and processes your content.