This page explains Genezio API authentication: how to send an API key, how to limit it, and how to exchange it for an OAuth 2.0 token. Each request sends an API key. A key belongs to one account and reads the data of that account only.

Send the API key in a header

Send the key in the X-API-Key header:
The Authorization header also works, for an HTTP client that has a field for a bearer token only:
A request with no key, or with a key that is incorrect, expired or revoked, gets 401.

The limits of an API key: access, brands and expiration

The owner of the account sets the limits of a key when they make it.
Give each program its own key, with the fewest brands that it needs. Then a key that leaks reads less data, and you revoke the key of one program only.

API keys and your plan

The plan of your account gives the number of API keys that the account can hold at the same time. The API Keys page of the dashboard shows the keys that you use and the limit of your plan.
  • When the account holds each key that the plan permits, a new key gets 403. Revoke a key, or change the plan.
  • When the plan does not include API access, each key of the account gets 403 forbidden, also a key that you made before.

Revoke an API key

In API Keys, select the trash icon of the key. The key and each token of the key stop at that moment.

OAuth 2.0 tokens with client credentials

A program that uses OAuth 2.0 can exchange the key for a token of 30 minutes. The dashboard shows the client_id of the key beside the key.
Send the token as Authorization: Bearer <token>. The token has the limits of its key.