Every request to the BotDigit Developer Platform (`/api/developer/v1/*`) must include a valid, scoped Personal Access Token (PAT) or Agency Application credential.
BotDigit tokens use a cryptographically structured format:
Transmit the credential in the standard Authorization HTTP header:
Authorization: Bearer bdt_pat_a98f12cb_f7281928374618293847281928374618Alternatively, environments unable to set Authorization headers may pass X-Api-Key: bdt_pat_....
BotDigit stores exclusively the SHA-256 digest of your secret token. Candidate lookups use the public 8-character prefix, verified with constant-time XOR comparison.
Revoking a token in your Developer Console instantly terminates access. Subsequent requests immediately fail-closed with HTTP 401 Unauthorized.
Developer tokens are strictly quarantined from financial routes. Wallet transfers, escrow releases, and payment methods reject PATs at the gateway level.
| Scope String | Read | Draft / Stage | Commitment Gate | Description |
|---|---|---|---|---|
| projects.read | ✓ | — | Autonomous | Discover and query open marketplace projects with sanitized fields. |
| proposals.read | ✓ | — | Autonomous | Inspect proposals and proposal drafts authored by the authenticated freelancer. |
| proposals.draft | — | ✓ | Autonomous | Stage AI-generated proposal drafts without consuming monthly bid quota or submitting to client. |
| proposals.submit | — | — | Human Approval | Authorize and execute human commitment to submit a staged proposal to the marketplace. |
| contracts.read | ✓ | — | Autonomous | Read active contracts, milestone terms, and escrow funding status. |
| deliveries.draft | — | ✓ | Autonomous | Stage completed milestone deliverables for human review prior to client submission. |
| deliveries.submit | — | — | Human Approval | Authorize and commit milestone delivery release to client for review and escrow approval. |
| messages.read | ✓ | — | Autonomous | Read message threads and conversation history for authorized projects. |
| messages.draft | — | ✓ | Autonomous | Stage draft responses in conversation threads for human review. |
| messages.send | — | — | Human Approval | Authorize sending messages directly to clients after human review. |
| workspaces.read | ✓ | — | Autonomous | Inspect Agency OS multi-seat workspaces, team members, and shared workspace projects. |
| webhooks.manage | ✓ | ✓ | Autonomous | Register, list, and revoke outbound HTTPS webhook event subscriptions. |