🔑 How Authentication Works
- Pass your API key in the Api-Key header using HTTP Basic Auth.
- No username or password is required — just the API key.
- All requests must be made over HTTPS; requests over plain HTTP are rejected.
- Invalid or missing keys will return a 401 Unauthorized.
❗️ Keep your API keys secure. They grant full access to your account and should never be shared publicly or within internal tools like Slack or dashboards.
Sandbox Environment
- In the sandbox, API keys are scoped to individual developer accounts.
- Keys generated in sandbox are not visible to teammates, even if production keys are shared across the org.