Authentication

How Soldgraph API keys work: send the key as a bearer token, use one key per project, keep keys on your server, and revoke a leaked key.

Every request needs an API key. Send it in the Authorization header as a bearer token.

Header
Authorization: Bearer sg_your_key_here

Keys start with sg_. Create, name and revoke them on the API keys page.

#Keys are shown once

When you create a key, the dashboard shows the full key one time. After that we only keep a hash, so nobody, including us, can read it back. If you lose a key, revoke it and create a new one.

#Use a key per project

You can create as many keys as you like. One key per app, script or environment makes it easy to see where traffic comes from in Logs, and to cut off one project without touching the rest.

#Keep keys on the server

Call Soldgraph from your server, a serverless function or a script, and send your own users the result. Browser requests from sites we haven't allowed return 403 origin_not_allowed.

#If a key leaks

  1. Open API keys and click Revoke next to it. It stops working right away.
  2. Create a new key and update your environment variable.
  3. Check Logs for requests you don't recognize.

#Errors

A missing, malformed or revoked key returns 401:

401 Unauthorized
{ "error": { "code": "invalid_api_key" } }

Errors are never charged.