Authentication

Every API request carries a Merki API key as a bearer token.

Quick path

  1. Issue a key and store it in an environment variable or secrets manager.
  2. Send it on every request: Authorization: Bearer <key>.
  3. On 401, rotate the key. It was revoked or never valid. See API keys.

Details

TopicDecision
SchemeAuthorization: Bearer <key> on all endpoints. No query-string keys.
Key formatPrefixed, random, per account. The prefix identifies the key for support and appeals without exposing it.
ScopesKeys inherit the issuing account's tier and access. There are no per-key scopes; use separate accounts to separate access. See Access tiers.
RotationIssue a new key, update tooling, then revoke the old one. Revoked keys stay revoked.
BYOKProvider keys you register are stored encrypted and never returned after registration. See Bring your own key.

Checklist

  • [ ] No key is committed to git or published anywhere public.
  • [ ] Tooling reads the key from the environment.
  • [ ] You know how to rotate after a revocation. See API keys.

Next step

Make a first call: Quickstart.