Authentication

API keys for device endpoints, session tokens for account management.

The API uses two authentication methods depending on the endpoint.

API key authentication

Used for device valuation endpoints (/devices/*). Pass your key via either header:

Authorization: Bearer YOUR_API_KEY
X-API-Key: YOUR_API_KEY

API keys are opaque 48-character hex strings. Create them via POST /account/keys.

Session token authentication

Used for account management endpoints (/account/*). Get a JWT by logging in with POST /auth/login, then pass it as a Bearer token:

Authorization: Bearer YOUR_ACCESS_TOKEN

Session tokens expire after 1 hour. Use POST /auth/refresh to get a new one.

Origin-restricted keys (client-side)

Any API key can optionally have allowed_origins set, making it safe to embed in frontend JavaScript:

  • Origin validation — the Origin header must match one of the key's allowed origins. Requests without an Origin header are rejected.
  • Per-IP rate limiting — 60 requests per minute per client IP, in addition to the per-key rate limit.

Keys without allowed_origins work from anywhere and should be kept secret (server-side use only).

Client-side example

// Create a key with origin restrictions:
// POST /account/keys { "allowed_origins": ["https://your-site.com"] }

const API_KEY = 'your_origin_restricted_key';

async function getDeviceValue(deviceId) {
  const res = await fetch(
    `https://api.trusttrade.com/v1/devices/${deviceId}`,
    { headers: { 'X-API-Key': API_KEY } }
  );
  if (!res.ok) throw new Error(`API error: ${res.status}`);
  return res.json();
}

See the client-side usage guide for more details.