Skip to content
APIonWeb

Developer Docs

Authentication

Browse documentation

Every request to the APIonWeb API is authenticated with an API key sent as a Bearer token in the Authorization header. There is no separate OAuth flow, session cookie, or signed-request scheme — every endpoint under /v1/* expects this header.

HTTP header
Authorization: Bearer 12|abcdEFGH1234567890abcdEFGH1234567890abcd

Where keys come from

API keys are issued through Laravel Sanctum's personal access tokens. Each key looks like {id}|{40-character-token} — a numeric token id, a pipe, then a 40-character random string. The full key is shown exactly once, at creation time, in your dashboard . APIonWeb only ever stores a hash of it — if you lose a key, revoke it and create a new one, you cannot retrieve the original value again.

Authentication failures

Two distinct error codes cover authentication problems, both returned with HTTP status 401:

Code When it happens
authentication_required No Authorization header was sent at all.
invalid_api_key The key is malformed, unknown, or has been revoked from the dashboard.

Missing header:

401 Unauthorized
{
  "error": {
    "code": "authentication_required",
    "message": "Authentication is required to access this resource."
  }
}

Invalid or revoked key:

401 Unauthorized
{
  "error": {
    "code": "invalid_api_key",
    "message": "The provided API key is invalid or has been revoked."
  }
}
API keys grant full access to your account balance. Never embed a key in client-side JavaScript, a mobile app binary, or a public repository — call APIonWeb from your own backend and proxy results to the client.

See API Keys for how to create, view, and revoke keys, and Errors for the full error reference.