Send a bearer key
Authenticated Market Data API requests use Authorization: Bearer YOUR_API_KEY. Send keys from your server or a trusted backend. The public plan list is the only route in this reference that does not require a key.
Authorization: Bearer YOUR_API_KEYKeep keys private
Do not place a key in a public frontend, URL, repository, or image upload. Each key belongs to an account, and account limits are shared by all of its active keys. Replace or revoke a key if it is exposed.
Inspect usage
Call GET /v1/usage to see the current account limit and remaining allowance. The usage call consumes one request. Response headers include x-request-id, x-ratelimit-remaining, and x-monthly-remaining.
Workspace access is separate
CardCounter POS shop routes under /api/v1 use the signed-in staff session and shop permissions. A Market Data API key does not grant access to shop records.