Getting started
API Authentication
How a school admin creates a Sky Schedule API key, how to send it in the Authorization or X-SkySchedule-API-Key header, and how to rotate or revoke it.
Every request to the Sky Schedule API, REST or MCP, carries your school's API key. API authentication is per school: the key belongs to the organization, not to a person, and only a school admin can create, rotate, or revoke it.
Create an API key
You need to be an admin of the school. Instructors, students, and renters can't see or manage keys.
- Sign in at
https://app.skyschedule.ioas an admin. - Open Settings and choose Integrations.
- Find API Keys in the list and click Connect (or Learn More if it already shows Connected).
- Click Generate API Key.
- Copy the key right away with the copy button next to it. The eye button shows or hides it.
If your school doesn't have API access on its plan yet, Generate API Key opens checkout first.
The key is shown once
Sky Schedule stores only a hash of the key, so it can't show you the full key again later. The browser you generated it in keeps a copy so the API Keys panel can show it on that device. On any other device you'll see only the start of the key. If you lose it, rotate it and update your integrations.
Key format
Keys start with ss_live_ followed by 32 characters made of letters, digits, -, and _. Anything else is rejected with 401 Invalid API key format.
Send the key with each request
Use either header. Both work for REST and MCP.
Authorization: Bearer ss_live_YOUR_API_KEY
X-SkySchedule-API-Key: ss_live_YOUR_API_KEY
If a request has both, the X-SkySchedule-API-Key value is used.
curl
curl -s "https://app.skyschedule.io/api/v1/instructors?limit=10" \
-H "Authorization: Bearer $SKYSCHEDULE_API_KEY"
JavaScript (Node 18 or later)
const res = await fetch("https://app.skyschedule.io/api/v1/customers?limit=25", {
headers: { Authorization: `Bearer ${process.env.SKYSCHEDULE_API_KEY}` },
});
if (!res.ok) throw new Error((await res.json()).error);
const { data, meta } = await res.json();
Python
import os
import requests
res = requests.get(
"https://app.skyschedule.io/api/v1/flights",
params={"from": "2026-10-01", "to": "2026-10-07"},
headers={"X-SkySchedule-API-Key": os.environ["SKYSCHEDULE_API_KEY"]},
timeout=30,
)
res.raise_for_status()
flights = res.json()["data"]
One key per school, shared by REST and MCP
A school has one active key at a time, and the same key works for the REST API and the MCP server. Keep that in mind before you rotate:
- Rotating the key, from API Keys or from Connect with your agent, revokes the old key at once. Every script and every connected agent that still uses it starts getting
401 Invalid or revoked API key.until you give it the new one. - Disconnect in Connect with your agent revokes the key without issuing a new one. REST requests stop working too.
Rotate a key
- Open Settings, Integrations, API Keys.
- Click Rotate key.
- Copy the new key and update every script and agent that used the old one.
Revoke a key
Open Settings, Integrations, then the Connect with your agent card, and click Disconnect. This removes the school's active key. Generate a new one any time with Generate API Key.
Keep the key safe
- Treat the key like an admin password. It can read the names, emails, and phone numbers of your customers and instructors. Through MCP, the same key can book, cancel, and void reservations, email CRM leads, and draft invoices.
- Keep it on a server, in an environment variable or a secret manager. Never put it in a web page, a mobile app, or a shared spreadsheet, and never commit it to a code repository.
- Rotate it when someone who had it leaves, or if you think it was exposed.
Authentication errors
| Status | Error message | What to check |
|---|---|---|
| 401 | Missing API key. Use Authorization: Bearer <key> or X-SkySchedule-API-Key. | The header is missing or the Bearer prefix is misspelled. |
| 401 | Invalid API key format. | The value doesn't start with ss_live_ or was cut off when copied. |
| 401 | Invalid or revoked API key. | The key was rotated or revoked. Use the current key. |
| 403 | Public API subscription is not active. | The school's API access isn't active. A school admin can check it under Settings, Integrations. |
Requests rejected for a missing or bad key don't count toward your daily limit. For every other status code, see rate limits and errors. To connect an AI agent with this key, follow MCP setup.