master-zapier-plan-draft/docs/03-zapier/auth.md
George Lambert b4150c8250 Milestone 0: import zappier billing, Verae middleware, and Zapier research
Compose-ready workspace: packages/zappier (rate card, portal, Stripe),
packages/verae-zapier-middleware (timestamp + NATS), packages/verae-zapier
(CLI app), vendor/zapier-platform, and research/zapier vendor corpus.

Gate 0 structure checks pass. Product code and research are not yet wired.
2026-09-09 02:37:36 -04:00

587 B

Zapier authentication

Target (after PR 5)

  • Type: custom / API key.
  • Fields: apiKey, baseUrl (default public zappier origin).
  • Header: x-api-key.
  • Test: GET /v1/status or GET /v1/me if added.
  • Errors: 401 invalid key; 403/402 quota or unpriced endpoint → user-visible upgrade text pointing at /portal.

Today (imported CLI app)

  • Bearer middleware API key zmw_….
  • Test: GET /zapier/v1/auth/me.
  • afterResponse maps 402 and PLAN_UPGRADE_REQUIRED.

Do not send Verae JWTs to Zapier. Middleware (or zappier→middleware) logs into Verae server-side.