Skip to documentation
DOCUMENTATIONAuthentication
BUILD AN INTEGRATION

Authentication

Use an account API key to authenticate server-side requests.

Send a bearer key

Authenticated Market Data API requests use Authorization: Bearer YOUR_API_KEY. Send keys from your server or a trusted backend. The public plan list is the only route in this reference that does not require a key.

REQUEST HEADERAuthorization: Bearer YOUR_API_KEY

Keep keys private

Do not place a key in a public frontend, URL, repository, or image upload. Each key belongs to an account, and account limits are shared by all of its active keys. Replace or revoke a key if it is exposed.

Inspect usage

Call GET /v1/usage to see the current account limit and remaining allowance. The usage call consumes one request. Response headers include x-request-id, x-ratelimit-remaining, and x-monthly-remaining.

Workspace access is separate

CardCounter POS shop routes under /api/v1 use the signed-in staff session and shop permissions. A Market Data API key does not grant access to shop records.

Read about the Workspace API