Authentication
API keys for device endpoints, session tokens for account management.
The API uses two authentication methods depending on the endpoint.
API key authentication
Used for device valuation endpoints (/devices/*). Pass your key via either header:
API keys are opaque 48-character hex strings. Create them via POST /account/keys.
Session token authentication
Used for account management endpoints (/account/*). Get a JWT by logging in with POST /auth/login, then pass it as a Bearer token:
Session tokens expire after 1 hour. Use POST /auth/refresh to get a new one.
Origin-restricted keys (client-side)
Any API key can optionally have allowed_origins set, making it safe to embed in frontend JavaScript:
- Origin validation — the
Originheader must match one of the key's allowed origins. Requests without anOriginheader are rejected. - Per-IP rate limiting — 60 requests per minute per client IP, in addition to the per-key rate limit.
Keys without allowed_origins work from anywhere and should be kept secret (server-side use only).
Client-side example
See the client-side usage guide for more details.