Authentication and permissions
Requests to the Robopack public V1 API use an API key in the X-API-Key HTTP header:
X-API-Key: <your-api-key>
Open Settings > API Integration in Robopack and select Create API key. This area also contains API Documentation, the interactive API browser. Use the API key value from that area as the credential for your integration.
Existing keys have controls to enable or disable them and Regenerate key. If you regenerate a key, update the integrations that use it with the new value. Coordinate that change so scheduled scripts have the current credential.
Use the key in scripts
The guides read a ROBOPACK_API_KEY environment variable so the key does not need to appear in the script source. For hosted automation, populate it from your platform's secret store. Keep the key out of source control, shared command output, and support attachments.
For curl, add this header to each request:
--header "X-API-Key: ${ROBOPACK_API_KEY}"
For PowerShell, create a header dictionary and pass it with -Headers:
$headers = @{
'X-API-Key' = $env:ROBOPACK_API_KEY
Accept = 'application/json'
}
Send requests over HTTPS to https://api.robopack.com/. Only the documented /v1/ endpoints are supported for external integrations; endpoints observed in the portal's browser network traffic may be internal.
Tenant permissions
An API key does not remove the need for Robopack tenant permissions. Robopack uses virtual API users, and some operations require additional permissions for the tenant being accessed.
| Task | Documented tenant permission |
|---|---|
| Read Radar data | See / read information |
| Create, modify, or delete Robopatch flows | Upload apps |
| Import packages to an Intune tenant | Upload apps |
The Radar and flow requirements are documented in the API FAQ. The tenant upload permission is described in Configure Roles & Permissions. For the wider access model, see Roles & Permissions.
Current limitation for virtual API users
Virtual API users appear under Settings > Users, but cannot currently be selected in the tenant permission Direct assignments dropdown. The documented workaround is to grant the selected tenant permission to all users in the organisation.
This workaround broadens access for every user in your Robopack organisation, not just the API user. An administrator should review Settings > Users, select only the required tenant and permission, and decide whether that wider access is acceptable before saving. If it is not acceptable, contact support to discuss your access requirements. See the FAQ warning and walkthrough.
If your administrator approves that access:
- Go to Settings > Tenants.
- Under Tenant permissions, select + Add tenant permission.
- Select the target tenant and the specific permission required.
- Select Grant to all users in organization.
- Select Save changes.
Repeat only for the tenants your integration needs to access. The Known Limitations page tracks this API-user assignment issue.
Robopack permissions and Intune consent
Robopack tenant permissions control what the API user can do in Robopack. The tenant's Microsoft Entra application consent controls Robopack's access to Intune. A tenant may need both the appropriate API-user permission and a working, consented Intune connection.
For an Intune upload, start with a connected Intune tenant. For Radar, also review the Radar requirements for the tenant connection. Those Microsoft Graph permissions are configured on the tenant connection; the API requests in these guides still authenticate to Robopack with X-API-Key.
Diagnose access problems
Verify the key is present and that your script is calling the supported API host and path. For a tenant-specific failure, confirm the UUID belongs to the intended tenant and review the virtual API user's tenant permissions. If the request reaches Intune but the operation fails, review the tenant connection and consent.
Do not assume every failure is a permissions problem or grant broader permissions without checking the operation and tenant. The OpenAPI source does not define an error payload contract, key expiry rules, or a rate-limit policy; use the actual response and contact support when needed.