Developer Docs
Authentication
Browse documentation
Introduction
API Reference
Account & Billing
Every request to the APIonWeb API is authenticated with an API key sent as a
Bearer token in the Authorization
header. There is no separate OAuth flow, session cookie, or signed-request scheme — every endpoint under
/v1/* expects this header.
Authorization: Bearer 12|abcdEFGH1234567890abcdEFGH1234567890abcd
Where keys come from
API keys are issued through Laravel Sanctum's personal access tokens. Each key looks like
{id}|{40-character-token} —
a numeric token id, a pipe, then a 40-character random string. The full key is shown exactly once, at
creation time, in your
dashboard
. APIonWeb only ever stores a hash of it — if you lose a key, revoke it and create a new one, you cannot
retrieve the original value again.
Authentication failures
Two distinct error codes cover authentication problems, both returned with HTTP status
401:
| Code | When it happens |
|---|---|
| authentication_required | No Authorization header was sent at all. |
| invalid_api_key | The key is malformed, unknown, or has been revoked from the dashboard. |
Missing header:
{
"error": {
"code": "authentication_required",
"message": "Authentication is required to access this resource."
}
}
Invalid or revoked key:
{
"error": {
"code": "invalid_api_key",
"message": "The provided API key is invalid or has been revoked."
}
}
See API Keys for how to create, view, and revoke keys, and Errors for the full error reference.