> ## Documentation Index
> Fetch the complete documentation index at: https://docs.azvian.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API & Webhooks

> Authenticate with a personal access token, and receive signed webhook events

## Authentication

Tenants generate their own personal access token from **Account → API Tokens**, then authenticate every request with:

```
Authorization: Bearer <token>
```

Each token is scoped to the tenant account that created it — there's no way for a token to reach another tenant's data.

## Endpoints

The API currently covers websites and reports:

| Method | Endpoint                     | Description                              |
| ------ | ---------------------------- | ---------------------------------------- |
| `GET`  | `/api/user`                  | The authenticated tenant's own user info |
| `GET`  | `/api/v1/websites`           | List your tracked websites               |
| `GET`  | `/api/v1/websites/{website}` | A single website's detail                |
| `GET`  | `/api/v1/reports/{report}`   | A single report's result                 |

<Info>See `routes/api.php` in your installation for the definitive, current endpoint list — this platform's roadmap notes the API surface is expected to grow over time.</Info>

## Webhooks

Register your own endpoint URL under **Account → Webhook Endpoints** to be notified of:

* `report.completed`
* `report.failed`

Each delivery is a signed JSON `POST` to your endpoint, with an `X-Webhook-Signature` header — an HMAC-SHA256 of the raw request body, keyed by your endpoint's own secret (shown once when you create the endpoint). Verify this signature before trusting a delivery.

Failed deliveries are automatically retried with backoff — you don't need to build your own retry logic for transient failures on your end.
