Stable contract 2026-08
API reference
Authentication, request conventions, error handling and the currently exposed App Platform contract.
Authentication
Server calls use short-lived bearer tokens issued to a registered app. Embedded browser code uses a one-time install-session exchange and never receives the client secret.
POST /api/app-platform/token
Content-Type: application/json
{
"clientId": "jotify_…",
"clientSecret": "read-once-secret",
"scope": "site:read site:content:write"
}Version every request
Send X-Jotify-Api-Version: 2026-08. Future stable versions use date-based identifiers and retain an overlap window before retirement.
const client = new JotifyApiClient({
baseUrl: 'https://jotify.com',
accessToken: process.env.JOTIFY_ACCESS_TOKEN
});
const identity = await client.get('/api/app-platform/me');
