Skip to main content

Overview

API keys provide long-lived authentication for:
  • Automated trading bots
  • Server-to-server integrations
  • CI/CD pipelines
  • Third-party app integrations
Unlike JWT tokens, API keys don’t expire automatically and can be scoped to specific permissions.

Creating an API Key

Response

The full API key (key field) is only returned once at creation time. Store it securely — it cannot be retrieved again.

Using an API Key

Include the key in the Authorization header with the ApiKey prefix:

Available Scopes

Managing API Keys

List Keys

Revoke a Key

Revoking an API key is immediate. Any requests using that key will receive a 401 error.

Restricted Endpoints

When using API keys, certain endpoints enforce scope-based access through the /restricted path:
The restricted endpoint validates that your API key has the required scope for the requested resource.

Best Practices

1

Use descriptive names

Name keys after their purpose: “Production Trading Bot”, “Backtest Runner”, “Portfolio Dashboard”
2

Apply least-privilege scopes

Only grant the scopes the integration actually needs. A monitoring dashboard only needs read:* scopes.
3

Rotate keys periodically

Create a new key, update your integration, then revoke the old key.
4

Use environment variables

Never hardcode API keys in source code. Use environment variables or secret managers.
5

Monitor usage

Check the lastUsed field to identify unused keys that should be revoked.