Authentication
Every API request carries a Merki API key as a bearer token.
Quick path
- Issue a key and store it in an environment variable or secrets manager.
- Send it on every request:
Authorization: Bearer <key>. - On
401, rotate the key. It was revoked or never valid. See API keys.
Details
| Topic | Decision |
|---|---|
| Scheme | Authorization: Bearer <key> on all endpoints. No query-string keys. |
| Key format | Prefixed, random, per account. The prefix identifies the key for support and appeals without exposing it. |
| Scopes | Keys inherit the issuing account's tier and access. There are no per-key scopes; use separate accounts to separate access. See Access tiers. |
| Rotation | Issue a new key, update tooling, then revoke the old one. Revoked keys stay revoked. |
| BYOK | Provider keys you register are stored encrypted and never returned after registration. See Bring your own key. |
Checklist
- [ ] No key is committed to git or published anywhere public.
- [ ] Tooling reads the key from the environment.
- [ ] You know how to rotate after a revocation. See API keys.
Next step
Make a first call: Quickstart.