Authentication
Send your API key as a bearer token
Every request carries one API key, in the Authorization header, and nowhere else.
The header
A key is hat_live_ or hat_test_ followed by 40 letters and digits. Anything else in the header is refused with a 401 before anything is looked up.
Never in a URL
The API does not read a key from a query parameter. A URL ends up in proxy logs, browser history and analytics, so a key there is a key leaked.
Shown once
Hatcel keeps only a fingerprint of a key, never the key itself, so it is shown once when it is made. Lost it? Revoke it and make another.
Revoking a key
In Settings > Developers, select the key and revoke it. Anything using it is refused from the next request. A revoked key, an unknown key and a key whose member was removed all get the same 401, so nobody can learn which keys exist or once did.
Guessing is throttled
After 30 refused keys in a minute from one address, that address gets a 429 until the minute is up. An IPv6 address is counted by its /64, so rotating through one network's addresses does not help.