Authentication

API keys

Every /v1 request carries an API key in the Authorization header. Keys belong to your account, and every extract counts against your account’s daily limit.

Use the standard bearer scheme on every request:

shell
curl http://localhost:4000/v1/usage -H "Authorization: Bearer ue_live_your_key_here"
200 OK
{ "day": "2026-10-07", "used": 3, "limit": 20 }

GET /v1/usage is a handy way to check that a key works: it doesn’t use up an extract.

Creating and revoking keys

Manage keys in your dashboard. Give each one a name that says where it lives (“Production server”, “Laptop”), so you know what breaks when you revoke it.

WhatHow it works
Formatue_live_ followed by 43 random characters
ShownOnce, when you create it. We store only a SHA-256 hash, so we can’t show it again or recover it.
LimitUp to 10 active keys per account
RevokingTakes effect immediately. Requests with that key get 401 invalid_api_key.
Last usedThe dashboard shows when each key was last used, to help you find unused ones.

Keeping keys safe

Treat an API key like a password. Anyone who has it can run extracts on your account.
  • Call the API from your server or scripts, never from code that runs in a visitor’s browser or a mobile app.
  • Load it from an environment variable or a secrets manager. Don’t commit it to git.
  • Use one key per app or environment, so you can revoke one without touching the others.
  • If a key leaks, revoke it in the dashboard and create a new one. Rotating takes a minute.

Authentication errors

StatuscodeMeaning
401missing_api_keyNo Authorization: Bearer header was sent.
401invalid_api_keyThe key is wrong, or it was revoked.
401 Unauthorized
{ "error": "This API key is not valid or was revoked.", "code": "invalid_api_key" }