API Key
All endpoints require authentication via theX-API-Key header, except GET /health.
Roles
Device Scoping
Non-admin users are restricted to specific devices using theallowed_hardware_ids field on their user record. This scoping applies to:
- REST API — all
/devices/:id/*routes,/lock-events,/trips - WebSocket —
subscribeandcommandmessages