Authentication

Every API Express request is authenticated with an API key. This guide covers how to get your key, how to use it, and how to manage it securely at scale.

Overview

API Express uses Bearer token authentication. You include your API key in the Authorization header of every request. All requests must be made over HTTPS — plain HTTP requests are rejected.

Authentication is uniform across all 10 APIs. Once you have a valid key, you can call any endpoint without additional setup. There are no separate credentials per API.

💡
First time here? Get your API key by signing up for a free account. Your key is issued instantly — no approval process, no waitlist.

API Keys

Your API key is a 32-character alphanumeric string that identifies your account to our servers. Every request you make includes this key, allowing us to track usage, enforce rate limits, and attribute activity to your account.

Key format

API keys follow this format:

sk_live_1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p

Prefixes identify the environment:

PrefixEnvironmentUse
sk_live_ProductionReal API calls, billed to your account
sk_test_SandboxTesting, mock data, no charges
⚠️
Never expose production keys in client-side code. Sandbox keys are safe to use in development environments. Production keys should only be used in server-side code.

Making Authenticated Requests

Include your API key in the Authorization header using the Bearer scheme. That's the only header required for authentication.

Basic request

curl "https://api.apiexpress.in/v1/weather?city=Mumbai" \
  -H "Authorization: Bearer sk_live_YOUR_API_KEY"

Node.js example

const response = await fetch(
  'https://api.apiexpress.in/v1/weather?city=Mumbai',
  {
    headers: {
      'Authorization': 'Bearer sk_live_YOUR_API_KEY'
    }
  }
);

const data = await response.json();
console.log(data);

Python example

import requests

response = requests.get(
    'https://api.apiexpress.in/v1/weather',
    params={'city': 'Mumbai'},
    headers={'Authorization': 'Bearer sk_live_YOUR_API_KEY'}
)

data = response.json()
print(data)

PHP example

$ch = curl_init('https://api.apiexpress.in/v1/weather?city=Mumbai');
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    'Authorization: Bearer sk_live_YOUR_API_KEY'
]);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = json_decode(curl_exec($ch), true);
✅
Using an SDK? Authentication is handled automatically. Just pass your key when initializing the client — see the SDKs guide.

Key Management

Your account supports multiple API keys — useful for separating use cases, rotating credentials, or granting different permissions to different services.

Recommended key strategy

For production applications, use separate keys for different purposes:

PurposeEnvironmentUse case
DevelopmentSandboxLocal dev, testing, prototyping
StagingSandboxPre-production testing with real integrations
Production — WebLiveServer-side API calls from your web app
Production — MobileLiveBackend-for-frontend service used by mobile apps

Rotating keys

You should rotate API keys periodically — every 90 days at minimum, and immediately if you suspect a key has been compromised. The rotation process has no downtime:

  1. Generate a new key in your dashboard
  2. Deploy the new key to your infrastructure
  3. Verify all services work with the new key
  4. Revoke the old key after 24-48 hours
💡
Both old and new keys work during the rotation window, allowing you to migrate without disruption. Never delete a key until you're certain no service depends on it.

Revoking keys

Revocation is immediate. Once a key is revoked, any request using it returns a 401 Unauthorized response. You can revoke keys from your dashboard at any time.

IP Whitelisting

For additional security, you can restrict your API keys to specific IP addresses. When IP whitelisting is enabled, requests from other IPs are rejected even if the key is valid.

IP whitelisting is available on Growth and Enterprise plans. To enable:

  1. Go to your dashboard → Security → IP Whitelisting
  2. Add the IP addresses or CIDR ranges you want to allow
  3. Enable enforcement for the keys you want to protect
⚠️
Test carefully before enforcing. If your production traffic comes from IPs you haven't whitelisted, those requests will fail. Verify your infrastructure's outbound IPs first.

Security Best Practices

Follow these practices to keep your API keys secure and your account safe:

Do

  • Store keys in environment variables — never hardcode them in your source code
  • Use different keys per environment — sandbox for dev, live for production
  • Rotate keys periodically — at least every 90 days
  • Use IP whitelisting for production keys when possible
  • Monitor usage in your dashboard for anomalies
  • Revoke compromised keys immediately — don't wait to investigate first

Don't

  • Commit keys to Git — even in private repositories
  • Embed production keys in client-side code — browsers, mobile apps, etc.
  • Share keys over email or chat — use a secrets manager instead
  • Use the same key across multiple applications — separate keys for separate systems
  • Send keys over HTTP — always use HTTPS (we reject HTTP requests anyway)
✅
Handling a leak? If a key is exposed, revoke it immediately in your dashboard and generate a new one. Old keys stop working within seconds of revocation.

Related Documentation

Ready to authenticate?

Get Your API Key in Under 2 Minutes

Sign up free, get your key instantly, and make your first authenticated request today. Your first 1,000 calls are on us.

No credit card required 1,000 free API calls Instant key delivery Sandbox included