Overview
API keys provide long-lived authentication for:- Automated trading bots
- Server-to-server integrations
- CI/CD pipelines
- Third-party app integrations
Creating an API Key
Response
Using an API Key
Include the key in theAuthorization header with the ApiKey prefix:
Available Scopes
Managing API Keys
List Keys
Revoke a Key
Revoking an API key is immediate. Any requests using that key will receive a
401 error.Restricted Endpoints
When using API keys, certain endpoints enforce scope-based access through the/restricted path:
Best Practices
1
Use descriptive names
Name keys after their purpose: “Production Trading Bot”, “Backtest Runner”, “Portfolio Dashboard”
2
Apply least-privilege scopes
Only grant the scopes the integration actually needs. A monitoring dashboard only needs
read:* scopes.3
Rotate keys periodically
Create a new key, update your integration, then revoke the old key.
4
Use environment variables
Never hardcode API keys in source code. Use environment variables or secret managers.
5
Monitor usage
Check the
lastUsed field to identify unused keys that should be revoked.
