Docs menu
First stepsAuthentication
Authentication
Every request carries a Bearer token: an API key from the account page.
Bearer tokens#
Every request to /v1/* carries one header:
Authorization: Bearer <token>The token is an API key. Every key of an account shares the account's burst limit and monthly quota.
API keys#
An API key is a prefix followed by a random body: lgv_ plus 64 characters in production. You create keys on /account, each with a name, up to 10 per account. The server stores only a hash; the account page keeps the prefix and the first 8 characters of the body so you can tell keys apart.
curl https://api.legivel.com/v1/usage \
-H "Authorization: Bearer $LEGIVEL_API_KEY"See Get your API key for the steps.
Failures#
A missing, malformed, expired or revoked token gets a 401 with a stable code and a WWW-Authenticate: Bearer header:
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer
Content-Type: application/json
{"code":"unauthorized","error":"missing or invalid bearer token"}A burst of unknown keys from one IP is throttled to keep the database out of the loop. Throttled requests still answer 401, so a misconfigured client sees 401 for a bad key, never 429.
Revocation#
Revoke a key on the account page (Revoke, then Confirm revoke). Verified keys are cached in the server for 60 seconds, and a database trigger evicts the cached entry the moment a key is deleted. In normal operation revocation is effective immediately; if that channel is down, the worst case is 60 seconds.
Security notes#
- Send keys only over HTTPS. The API is served over HTTPS; plain HTTP is redirected.
- Keep keys in environment variables or a secret store, not in source control.
- Use one key per deployment so revoking one does not break the others.
- Per-key usage on GET /v1/usage shows which key did what.