Getting started
Authentication
How to authenticate Public API requests with an API key created in the Developer Center dashboard.
API keys#
Public API keys are created in the Developer Center dashboard. A key is esk_live_ followed by 32 letters and digits, and it is shown only once when created.
Sending the key#
Send your API key in a header with every request. Keys start with esk_live_; use whichever header is convenient.
http
# Either header works
X-API-Key: esk_live_your_key_here
Authorization: Bearer esk_live_your_key_hereKeeping keys safe#
Warning
Keep keys on your server. Anything in browser or app code is visible to everyone. If a key leaks, revoke it in the dashboard and create a new one. Up to 5 active keys per account.
Partner API keys are different#
B2B keys issued in the partner portal (esk_live_<10>_<40>) have a different format and are rejected by the Public API, and vice versa. For Partner API authentication see Partner API authentication.
