Authentication
Every request to the API carries a key in the Authorization header:
Authorization: Bearer rfk_0194f2c0…_Qm3…Creating and revoking keys
Section titled “Creating and revoking keys”Keys are created in the portal, under API keys. A key is shown once, when you create it. We store only a hash, so a lost key cannot be recovered: create another and revoke the old one. Revoking takes effect at once.
You can have up to 25 active keys, for example one per environment or service.
Keep keys on your server
Section titled “Keep keys on your server”Anyone with a key can spend your credits. Call the API from your backend, never from a browser or a mobile app, and keep the key in an environment variable or a secret store.
Failures
Section titled “Failures”A missing, malformed or revoked key gets 401 unauthorized. Repeated failures from one
address are slowed down with 429. The error never repeats the key you sent.
{ "error": { "code": "unauthorized", "message": "A valid API key is required. Send it as `Authorization: Bearer <key>`." }}Each key has a request rate set by your plan; see Errors and limits.