Vani Logo Vani / API Docs v1
Access Vani
Getting started / Authentication

Authentication

Access to these APIs is secured with OAuth 2.0. An edition-scoped API key may accompany the access token.

OAuth 2.0
Use this authorization code flow method for secure, token-based access.
API Key
Include the API Key in the request header as x-vani-apikey to authorize access to resources.
Header: x-vani-apikey

OAuth 2.0 flow

Vani uses the standard OAuth 2.0 authorization code flow through Zoho Accounts.

  1. Register your applicationGet your client ID and secret from the Zoho API Console.
  2. Redirect the user to the authorization URLThe user grants the scopes you request.
  3. Exchange the authorization codeReceive an access token and a refresh token.
  4. Make API requestsSend the access token in the Authorization header.
  5. Refresh tokensUse the refresh token to mint new access tokens.

Endpoints

Authorisation is served by Zoho Accounts, not by the API host. Use the row for your edition's data centre — an OAuth client is valid only in the data centre it was registered in.

Data centreAuthorization endpointToken endpoint
.com default https://accounts.zoho.com/oauth/v2/auth https://accounts.zoho.com/oauth/v2/token
.in https://accounts.zoho.in/oauth/v2/auth https://accounts.zoho.in/oauth/v2/token
.eu https://accounts.zoho.eu/oauth/v2/auth https://accounts.zoho.eu/oauth/v2/token
.ca https://accounts.zohocloud.ca/oauth/v2/auth https://accounts.zohocloud.ca/oauth/v2/token
.com.au https://accounts.zoho.com.au/oauth/v2/auth https://accounts.zoho.com.au/oauth/v2/token
.sa https://accounts.zoho.sa/oauth/v2/auth https://accounts.zoho.sa/oauth/v2/token
.ae https://accounts.zoho.ae/oauth/v2/auth https://accounts.zoho.ae/oauth/v2/token

Example request

Every request carries an access token. Authorization accepts either Zoho-oauthtoken or Bearer — both work.

HTTP
GET /vani/api/v1/spaces HTTP/1.1
Host: api.app.vanihq.com
Authorization: Zoho-oauthtoken YOUR_ACCESS_TOKEN
Content-Type: application/json

Scopes & access levels

Scopes are granular. Every operation on the reference pages declares exactly the scopes it needs — request only those.

Scopes follow the resource nesting. Any operation on a zone can carry a space scope, and operations inside a zone can carry a zone scope — so a token scoped to a space reaches the zones within it. Grant the narrowest scope that covers the operations you call.

editions

Grants access to edition-level operations, including creating, updating, and managing editions, as well as adding or updating edition members.

MethodOAuth scope
GETVani.editions.READ
POSTVani.editions.CREATE
teams

Provides access to team-level operations within an edition, such as creating teams, updating details, managing members (add/remove/change roles), and deleting teams.

MethodOAuth scope
GETVani.teams.READ
POSTVani.teams.CREATE
PUTVani.teams.UPDATE
DELETEVani.teams.DELETE
spaces

Enables full control over Space-related operations within a team, including creating, updating, and deleting Spaces under a specific edition.

MethodOAuth scope
GETVani.spaces.READ
POSTVani.spaces.CREATE
PUTVani.spaces.UPDATE
DELETEVani.spaces.DELETE
zones

Allows Zone-level access within a Space, including creating, editing, and deleting Zones for detailed content management.

MethodOAuth scope
GETVani.zones.READ
POSTVani.zones.CREATE
PUTVani.zones.UPDATE
DELETEVani.zones.DELETE

Authentication errors

StatusMeaning
401Invalid or missing authentication credentials
403Valid credentials but insufficient permissions or scopes
429Rate limit exceeded — retry after the window resets
© 2026 Zoho Corporation Pvt. Ltd. Help