Authentication

Use a Bearer token in the Authorization header to access the API. The service accepts two token types:

- JWT access tokens

- Personal Access Tokens (PAT), which start with pat_

Prerequisites

  • A valid API token (JWT or PAT)

  • For JWT: your X-Tenant-Id value

  • If you’re unsure how to obtain these, contact our support team at support@dreamhub.ai

Make Your First Request

  • With JWT:

    • Headers:

      • Authorization: Bearer <YOUR_JWT>

      • X-Tenant-Id: <YOUR_TENANT_ID>

    • Example:

curl -X GET \
      -H "Authorization: Bearer &lt;YOUR_JWT&gt;" \
      -H "X-Tenant-Id: &lt;YOUR_TENANT_ID&gt;" \
      https://crm.dreamhub.ai/api/v1/endpoint
  • With PAT:

    • Headers:

      • Authorization: Bearer pat_<YOUR_PAT>
    • Example:

   curl -X GET \
      -H "Authorization: Bearer pat_&lt;YOUR_PAT&gt;" \
      https://crm.dreamhub.ai/api/v1/endpoint

Notes:

  • PAT tokens always begin with pat_ and do not require X-Tenant-Id.

  • JWT requests must include a correct X-Tenant-Id or they will be rejected.

Choosing A Method

  • Use JWT if your organization issues short‑lived access tokens and you use client-side code

  • Use PAT if use a server-based tool

Error Guide

  • 401 Unauthorized:

    • Missing Authorization header

    • Invalid or expired token

    • For JWT: missing/incorrect X-Tenant-Id

  • 403 Forbidden:

    • You are authenticated but lack required permissions for the endpoint

Best Practices

  • Always use HTTPS and send the Authorization header on every request

  • Do not share or hard‑code tokens; rotate regularly

  • Avoid logging full tokens; redact if you log requests

Troubleshooting

  • Verify the header format: Authorization: Bearer <token>

  • For PAT: ensure the token starts with pat_

  • For JWT: confirm X-Tenant-Id exactly matches your tenant ID

  • Check your token is current (not expired) and you’re calling the correct API base URL

Still stuck? Contact support@dreamhub.ai with the timestamp, endpoint, and the response status code (do not include your token)