Authentication
Every API Express request is authenticated with an API key. This guide covers how to get your key, how to use it, and how to manage it securely at scale.
Overview
API Express uses Bearer token authentication. You include your API key in the Authorization header of every request. All requests must be made over HTTPS — plain HTTP requests are rejected.
Authentication is uniform across all 10 APIs. Once you have a valid key, you can call any endpoint without additional setup. There are no separate credentials per API.
API Keys
Your API key is a 32-character alphanumeric string that identifies your account to our servers. Every request you make includes this key, allowing us to track usage, enforce rate limits, and attribute activity to your account.
Key format
API keys follow this format:
sk_live_1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p
Prefixes identify the environment:
| Prefix | Environment | Use |
|---|---|---|
sk_live_ | Production | Real API calls, billed to your account |
sk_test_ | Sandbox | Testing, mock data, no charges |
Making Authenticated Requests
Include your API key in the Authorization header using the Bearer scheme. That's the only header required for authentication.
Basic request
curl "https://api.apiexpress.in/v1/weather?city=Mumbai" \
-H "Authorization: Bearer sk_live_YOUR_API_KEY"
Node.js example
const response = await fetch(
'https://api.apiexpress.in/v1/weather?city=Mumbai',
{
headers: {
'Authorization': 'Bearer sk_live_YOUR_API_KEY'
}
}
);
const data = await response.json();
console.log(data);
Python example
import requests
response = requests.get(
'https://api.apiexpress.in/v1/weather',
params={'city': 'Mumbai'},
headers={'Authorization': 'Bearer sk_live_YOUR_API_KEY'}
)
data = response.json()
print(data)
PHP example
$ch = curl_init('https://api.apiexpress.in/v1/weather?city=Mumbai');
curl_setopt($ch, CURLOPT_HTTPHEADER, [
'Authorization: Bearer sk_live_YOUR_API_KEY'
]);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = json_decode(curl_exec($ch), true);
Key Management
Your account supports multiple API keys — useful for separating use cases, rotating credentials, or granting different permissions to different services.
Recommended key strategy
For production applications, use separate keys for different purposes:
| Purpose | Environment | Use case |
|---|---|---|
| Development | Sandbox | Local dev, testing, prototyping |
| Staging | Sandbox | Pre-production testing with real integrations |
| Production — Web | Live | Server-side API calls from your web app |
| Production — Mobile | Live | Backend-for-frontend service used by mobile apps |
Rotating keys
You should rotate API keys periodically — every 90 days at minimum, and immediately if you suspect a key has been compromised. The rotation process has no downtime:
- Generate a new key in your dashboard
- Deploy the new key to your infrastructure
- Verify all services work with the new key
- Revoke the old key after 24-48 hours
Revoking keys
Revocation is immediate. Once a key is revoked, any request using it returns a 401 Unauthorized response. You can revoke keys from your dashboard at any time.
IP Whitelisting
For additional security, you can restrict your API keys to specific IP addresses. When IP whitelisting is enabled, requests from other IPs are rejected even if the key is valid.
IP whitelisting is available on Growth and Enterprise plans. To enable:
- Go to your dashboard → Security → IP Whitelisting
- Add the IP addresses or CIDR ranges you want to allow
- Enable enforcement for the keys you want to protect
Security Best Practices
Follow these practices to keep your API keys secure and your account safe:
Do
- Store keys in environment variables — never hardcode them in your source code
- Use different keys per environment — sandbox for dev, live for production
- Rotate keys periodically — at least every 90 days
- Use IP whitelisting for production keys when possible
- Monitor usage in your dashboard for anomalies
- Revoke compromised keys immediately — don't wait to investigate first
Don't
- Commit keys to Git — even in private repositories
- Embed production keys in client-side code — browsers, mobile apps, etc.
- Share keys over email or chat — use a secrets manager instead
- Use the same key across multiple applications — separate keys for separate systems
- Send keys over HTTP — always use HTTPS (we reject HTTP requests anyway)
Related Documentation
- Error Codes — Handle 401 and other authentication errors
- Rate Limits — Understand usage limits per plan
- Sandbox Testing — Use test keys safely
- SDKs & Libraries — Let our SDK handle auth for you
Get Your API Key in Under 2 Minutes
Sign up free, get your key instantly, and make your first authenticated request today. Your first 1,000 calls are on us.