1. Partner API v2
  2. Guides
  3. Authentication
Guide

Authentication

Send your key in a header. Its client access and scopes decide what it can read.

Send your API key in the X-API-Key header on every request. Keys are generated in the partner dashboard under Settings → Integrations → API Keys.

A key has two properties that decide what it can do:

Client access
all clients under your partner account, or an explicit list of clients. A request for a client outside the key's access returns 403.
Scopes
read and/or write. Every operation in this document lists the scope it requires. A read-only key gets 403 on any write. Every 2.0 endpoint needs only read, so a read-only key is all a 2.0 integration needs.

GET /partner/api-key tells you what the key you are holding can do.

Check a key

GET /v2/partner/api-key returns the key you are calling with, its scopes, and its client access. Reference

curl "https://app.infimasecapis.com/v2/partner/api-key" \
  -H "X-API-Key: $INFIMA_API_KEY"