Authentication
Projects
Environments
Rows
Functions
Webhooks
Overview
API Reference
The Tessera REST API gives you programmatic access to projects, environments, rows, functions and webhooks.
Base URL
All endpoints live under a single versioned base URL. Every request must use HTTPS.
Authentication
Authenticate with a bearer token in the Authorization header. Use a server key from your project settings, or a user access token from Create token.
Keep server keys private
Server keys bypass row-level rules. Never ship them to a browser or mobile app.
Errors
Errors return a JSON body with a machine-readable code and a human-readable message.
Status
Meaning
400
The request is malformed or a grant is invalid.
401
The token is missing, expired or revoked.
403
The key lacks the scope for this endpoint.
404
The resource doesn’t exist in this environment.
422
Validation failed. See error.fields.
429
Rate limited. Retry after Retry-After seconds.
Rate limits
Each key can make 100 requests per second. Every response includes X-RateLimit-Remaining; when you hit the limit, wait for the number of seconds in Retry-After.
Pagination
List endpoints return up to 20 items and a next_cursor. Pass it as cursor to fetch the next page; it’s null on the last page.
Versioning
The version is part of the URL (/v1). Additive changes, like new fields or endpoints, ship without a version bump, so ignore fields you don’t recognise.
© 2026 Tessera, Inc.
Support
Status