Skip to contentSkip to navigation
Hatcel
Developers
2026-10-08API status

Authentication

Send your API key as a bearer token

Every request carries one API key, in the Authorization header, and nowhere else.

The header

Header
Authorization: Bearer hat_live_...

A key is hat_live_ or hat_test_ followed by 40 letters and digits. Anything else in the header is refused with a 401 before anything is looked up.

Never in a URL

The API does not read a key from a query parameter. A URL ends up in proxy logs, browser history and analytics, so a key there is a key leaked.

Shown once

Hatcel keeps only a fingerprint of a key, never the key itself, so it is shown once when it is made. Lost it? Revoke it and make another.

Revoking a key

In Settings > Developers, select the key and revoke it. Anything using it is refused from the next request. A revoked key, an unknown key and a key whose member was removed all get the same 401, so nobody can learn which keys exist or once did.

401
{
  "type": "https://developers.hatcel.com/errors#unauthorized",
  "title": "A valid API key is required",
  "status": 401,
  "code": "unauthorized",
  "request_id": "req_8c1f2e4b6a9d0c3e5f7a1b2c"
}

Guessing is throttled

After 30 refused keys in a minute from one address, that address gets a 429 until the minute is up. An IPv6 address is counted by its /64, so rotating through one network's addresses does not help.