Human In Circuit DocsAPI v2 · Contract 2.0.0
Browse all documentation

Start

OverviewQuickstartConceptsReview playground

Build

AuthenticationAPI ReferenceCallbacksTroubleshooting

Integrations

n8nZapier

Authentication

Authenticate every API request with the API key for one project.

API key scope

Every Human In Circuit API key belongs to exactly one project. A key cannot create reviews in multiple projects.

Each key is also permanently pinned to one URL-major API version. Current keys use v1; a future major upgrade creates a new key instead of changing an existing integration underneath a running workflow.

The project is selected when the key is generated:

Organization admin → API keys → New

The complete API key is displayed once. Copy it into the calling system's credential store instead of placing it directly in a shared workflow.

Request header

Send the key as a Bearer token:

Authorization: Bearer hic_your_api_key

Add the API key to n8n credentials

For an HTTP Request node that you build yourself:

  1. Open the node and set Authentication to Generic Credential Type.
  2. Select Header Auth.
  3. Create a credential named Human In Circuit.
  4. Set Name to Authorization.
  5. Set Value to Bearer hic_your_api_key.
  6. Save the credential and select it in the node.

The downloadable starter subworkflow also accepts api_key as an input for a faster first test. Move production keys into n8n credentials before sharing workflows or exporting them.

Project key

The project key is a readable project identifier, not an authentication secret.

You can copy it by opening Organization admin → Projects and expanding a project. It also appears in review-creation responses and callback bodies so you can distinguish projects.

Callback hostname restriction

The callback hostname setting is optional:

  • leave it blank to allow callbacks to any public HTTPS URL;
  • set a hostname to restrict callbacks to that host and its subdomains.

For this callback URL:

https://n8n.example.com/webhook-waiting/abc123

Enter:

n8n.example.com

Private, local, link-local, non-HTTPS, credential-bearing, and redirecting callback destinations remain blocked.

Idempotency

Production workflows should send an Idempotency-Key header:

Idempotency-Key: article-123-human-review

When the same integration retries with the same value, Human In Circuit returns the existing review rather than creating a duplicate.

Choose a stable value tied to the workflow item—not a new random value on every retry.