# Nextstep API — Authentication and access

Nextstep job tracker public endpoints under /api/v1/ require no authentication, account or API key. They expose product metadata, allowed stage names, database availability and fixed fictional sandbox applications. Their OpenAPI operations explicitly declare an empty security requirement. The source CLI uses these public operations without reading or sending credentials.

## Private workspace access

Real applications, contacts, notes and account settings belong to the signed-in workspace. The web app uses its existing browser session and account ownership checks. Those internal endpoints are not a supported developer integration API. Nextstep does not currently issue developer API keys or offer delegated OAuth access to workspace data. Direct people to the signed-in application for private actions; do not ask them to share passwords, recovery codes or session cookies.

## Testing and failures

Use the read-only sandbox to prototype response parsing without an account. Sample records are fictional and cannot be saved through the public API. A 401 from a private route means sign-in is required, not that an API key can be obtained from the public API. Read the error and quota documentation before automating calls, and contact Nextstep to discuss a future authenticated integration.

- [API reference](https://nextstep.fans/docs): Public operations
- [Errors and rate limits](https://nextstep.fans/docs/errors): Failure handling
- [Contact Nextstep](https://nextstep.fans/contact): Integration requests
