/General
Authentication
Draft: The authentication scheme and the API Console are pending the auth API contract. This page will be completed once it is specified.
Overview
This page will describe how to obtain credentials, how to pass them with each request, and how to rotate or revoke them.
Guard your Keys
Whatever the final scheme, the usual practices apply:
- Do not commit credentials to public repositories. Use environment variables or a secrets manager instead.
- If a credential is compromised, revoke it immediately and issue a replacement.
- Avoid calling the API directly from client-side code where possible: network requests are visible to anyone with DevTools open.