Authorization header of each request.
kal_ and has 43 more characters. To get a key, see Create an API key.
What a key can do
The key acts as you. It has the same routes, the same owner checks, and the same rate limit as your website session. Keys do not add to your rate limit.
The API reads the current state of your account on each request. If you verify your email, your keys get that access immediately.
Routes that need a website sign-in
These routes return403 session_required for an API key:
GET /api/keys,POST /api/keys,DELETE /api/keys/{key_id}POST /api/stripe/onboarding
Public routes
These routes do not need a key:GET /api/programsandGET /api/programs/{program_id}. A key is optional. With a key, you also see the private programs that invite you.POST /api/auth/password-reset
Authorization header that is empty or not valid, the API returns 401, also on public routes.
Errors
When a key stops working
- You delete it.
- It expires.
- You change your password. This ends all keys made before the change.
- Your account is disabled.
Keep keys secret
- Store keys in a secret manager or an environment variable.
- Do not put keys in reports, messages, logs, or source code.
- Kalligator stores only a hash of each key. Kalligator cannot show you a key again.