Skip to main content
Creating and using any API key requires approved individual or corporate verification, including sandbox keys. Suspension or revocation of approval blocks existing keys. Send your API key in the Authorization header:
Each key belongs to one company and one environment. The server derives both from the key; a request header cannot turn a sandbox key into a live key. Create and revoke keys in Developers in the company console. Each reference page lists the required permission. Full card details require cards:read_sensitive, separately from ordinary card access. Keep keys in server-side secret storage. Do not include them in mobile applications, browser bundles, shared screenshots, or documentation examples. An invalid or revoked key is rejected. The company console’s cookie session is separate from API-key authentication.