Skip to content

Authentication

Every request to the API carries a key in the Authorization header:

Authorization: Bearer rfk_0194f2c0…_Qm3…

Keys are created in the portal, under API keys. A key is shown once, when you create it. We store only a hash, so a lost key cannot be recovered: create another and revoke the old one. Revoking takes effect at once.

You can have up to 25 active keys, for example one per environment or service.

Anyone with a key can spend your credits. Call the API from your backend, never from a browser or a mobile app, and keep the key in an environment variable or a secret store.

A missing, malformed or revoked key gets 401 unauthorized. Repeated failures from one address are slowed down with 429. The error never repeats the key you sent.

{
"error": {
"code": "unauthorized",
"message": "A valid API key is required. Send it as `Authorization: Bearer <key>`."
}
}

Each key has a request rate set by your plan; see Errors and limits.