Getting started

API Authentication

How a school admin creates a Sky Schedule API key, how to send it in the Authorization or X-SkySchedule-API-Key header, and how to rotate or revoke it.

llms.txt

Every request to the Sky Schedule API, REST or MCP, carries your school's API key. API authentication is per school: the key belongs to the organization, not to a person, and only a school admin can create, rotate, or revoke it.

Create an API key

You need to be an admin of the school. Instructors, students, and renters can't see or manage keys.

  1. Sign in at https://app.skyschedule.io as an admin.
  2. Open Settings and choose Integrations.
  3. Find API Keys in the list and click Connect (or Learn More if it already shows Connected).
  4. Click Generate API Key.
  5. Copy the key right away with the copy button next to it. The eye button shows or hides it.

If your school doesn't have API access on its plan yet, Generate API Key opens checkout first.

The key is shown once

Sky Schedule stores only a hash of the key, so it can't show you the full key again later. The browser you generated it in keeps a copy so the API Keys panel can show it on that device. On any other device you'll see only the start of the key. If you lose it, rotate it and update your integrations.

Key format

Keys start with ss_live_ followed by 32 characters made of letters, digits, -, and _. Anything else is rejected with 401 Invalid API key format.

Send the key with each request

Use either header. Both work for REST and MCP.

Authorization: Bearer ss_live_YOUR_API_KEY
X-SkySchedule-API-Key: ss_live_YOUR_API_KEY

If a request has both, the X-SkySchedule-API-Key value is used.

curl

curl -s "https://app.skyschedule.io/api/v1/instructors?limit=10" \
  -H "Authorization: Bearer $SKYSCHEDULE_API_KEY"

JavaScript (Node 18 or later)

const res = await fetch("https://app.skyschedule.io/api/v1/customers?limit=25", {
  headers: { Authorization: `Bearer ${process.env.SKYSCHEDULE_API_KEY}` },
});
if (!res.ok) throw new Error((await res.json()).error);
const { data, meta } = await res.json();

Python

import os
import requests

res = requests.get(
    "https://app.skyschedule.io/api/v1/flights",
    params={"from": "2026-10-01", "to": "2026-10-07"},
    headers={"X-SkySchedule-API-Key": os.environ["SKYSCHEDULE_API_KEY"]},
    timeout=30,
)
res.raise_for_status()
flights = res.json()["data"]

One key per school, shared by REST and MCP

A school has one active key at a time, and the same key works for the REST API and the MCP server. Keep that in mind before you rotate:

  • Rotating the key, from API Keys or from Connect with your agent, revokes the old key at once. Every script and every connected agent that still uses it starts getting 401 Invalid or revoked API key. until you give it the new one.
  • Disconnect in Connect with your agent revokes the key without issuing a new one. REST requests stop working too.

Rotate a key

  1. Open Settings, Integrations, API Keys.
  2. Click Rotate key.
  3. Copy the new key and update every script and agent that used the old one.

Revoke a key

Open Settings, Integrations, then the Connect with your agent card, and click Disconnect. This removes the school's active key. Generate a new one any time with Generate API Key.

Keep the key safe

  • Treat the key like an admin password. It can read the names, emails, and phone numbers of your customers and instructors. Through MCP, the same key can book, cancel, and void reservations, email CRM leads, and draft invoices.
  • Keep it on a server, in an environment variable or a secret manager. Never put it in a web page, a mobile app, or a shared spreadsheet, and never commit it to a code repository.
  • Rotate it when someone who had it leaves, or if you think it was exposed.

Authentication errors

StatusError messageWhat to check
401Missing API key. Use Authorization: Bearer <key> or X-SkySchedule-API-Key.The header is missing or the Bearer prefix is misspelled.
401Invalid API key format.The value doesn't start with ss_live_ or was cut off when copied.
401Invalid or revoked API key.The key was rotated or revoked. Use the current key.
403Public API subscription is not active.The school's API access isn't active. A school admin can check it under Settings, Integrations.

Requests rejected for a missing or bad key don't count toward your daily limit. For every other status code, see rate limits and errors. To connect an AI agent with this key, follow MCP setup.