Authentication
API keys
Every /v1 request carries an API key in the Authorization header. Keys belong to your account, and every extract counts against your account’s daily limit.
Sending your key
Use the standard bearer scheme on every request:
shell
curl http://localhost:4000/v1/usage -H "Authorization: Bearer ue_live_your_key_here"200 OK
{ "day": "2026-10-07", "used": 3, "limit": 20 }GET /v1/usage is a handy way to check that a key works: it doesn’t use up an extract.
Creating and revoking keys
Manage keys in your dashboard. Give each one a name that says where it lives (“Production server”, “Laptop”), so you know what breaks when you revoke it.
| What | How it works |
|---|---|
| Format | ue_live_ followed by 43 random characters |
| Shown | Once, when you create it. We store only a SHA-256 hash, so we can’t show it again or recover it. |
| Limit | Up to 10 active keys per account |
| Revoking | Takes effect immediately. Requests with that key get 401 invalid_api_key. |
| Last used | The dashboard shows when each key was last used, to help you find unused ones. |
Keeping keys safe
Treat an API key like a password. Anyone who has it can run extracts on your account.
- Call the API from your server or scripts, never from code that runs in a visitor’s browser or a mobile app.
- Load it from an environment variable or a secrets manager. Don’t commit it to git.
- Use one key per app or environment, so you can revoke one without touching the others.
- If a key leaks, revoke it in the dashboard and create a new one. Rotating takes a minute.
Authentication errors
| Status | code | Meaning |
|---|---|---|
| 401 | missing_api_key | No Authorization: Bearer header was sent. |
| 401 | invalid_api_key | The key is wrong, or it was revoked. |
401 Unauthorized
{ "error": "This API key is not valid or was revoked.", "code": "invalid_api_key" }