This page explains Genezio API authentication: how to send an API key, how to
limit it, and how to exchange it for an OAuth 2.0 token. Each request sends an API key. A key belongs to one account and reads the
data of that account only.
Send the key in the X-API-Key header:
The Authorization header also works, for an HTTP client that has a field
for a bearer token only:
A request with no key, or with a key that is incorrect, expired or revoked, gets
401.
The limits of an API key: access, brands and expiration
The owner of the account sets the limits of a key when they make it.
Give each program its own key, with the fewest brands that it needs. Then a
key that leaks reads less data, and you revoke the key of one program only.
API keys and your plan
The plan of your account gives the number of API keys that the account can hold at the same time. The API Keys page of the dashboard shows the keys that you use and the limit of your plan.
- When the account holds each key that the plan permits, a new key gets
403. Revoke a key, or change the plan.
- When the plan does not include API access, each key of the account gets
403 forbidden, also a key that you made before.
Revoke an API key
In API Keys, select the trash icon of the key. The key and each token of
the key stop at that moment.
OAuth 2.0 tokens with client credentials
A program that uses OAuth 2.0 can exchange the key for a token of 30 minutes. The
dashboard shows the client_id of the key beside the key.
Send the token as Authorization: Bearer <token>. The token has the limits of
its key.