Docs
Authentication
Bearer keys, test vs live, rotation without downtime.
The header
Send your key as a Bearer token on every request:
header
Authorization: Bearer as_test_YOUR_KEYTest and live keys
| Prefix | Data | Billing |
|---|---|---|
as_test_ | Fictional sandbox entities | Never billed. Responses include meta.live_price_inr. |
as_live_ | Live sources | Successful calls only, debited from your wallet. Not enabled in this prototype. |
Keeping keys safe
- Keys are shown once. Store them in your secret manager, not in source control.
- Call the API from your backend — never ship a key to a browser or mobile app.
- Use one key per service so you can revoke one without touching the others.
Rotation
Create a new key in API keys, deploy it, then revoke the old one. Both work in between, so there is no downtime.
Auth errors
A missing or malformed key returns 401 AUTH_INVALID_KEY. A valid key without access returns 403 AUTH_SCOPE_DENIED. Both are billed ₹0.