Authentication
API keys, the bearer header, permissible-use certification, rotation and revocation.
Every request is authenticated with an API key sent as a bearer token:
Authorization: Bearer <your API key>A missing, malformed or revoked key is answered 401 with code: "unauthorized". No request runs before the key is checked.
Getting a key
Keys are created in the app under API keys by an owner of the organization. Before the first key is issued, the owner certifies the purpose the results will be used for — exclusion screening is regulated, and the certification is recorded against the organization. Every plan may create keys.
A key is shown once, at creation. We store only a hash of it, so a lost key cannot be recovered — rotate it instead.
Rotating and revoking
- Rotate issues a new key and retires the old one. Deploy the new key, then rotate.
- Revoke stops a key immediately. Do it whenever a key may have leaked.
Keeping keys safe
- Call the API from your server. A key in a browser or mobile app is a key anyone can read.
- One key per environment (production, staging) so you can revoke one without the other.
- Never commit a key. Load it from an environment variable or a secret manager.
Rate limits and allowances
Limits are per key and resolved from your plan on every call — see Rate limits.
