Skip to content

Send your API key in the Authorization header of every request:

Authorization: Bearer mdw_live_<random characters>
  • A key is mdw_live_ followed by 32 lowercase characters (a-z, 2-7). Only a hash is stored: the key is shown once, when you create it.
  • Keys belong to your account, and credits belong to the account, not to a key. Revoking or replacing a key never changes your balance.
  • An account can have up to 10 active keys. Create, rename and revoke them in the dashboard under API keys.
  • GET /v1/health is the only endpoint without authentication.

Create a new key, switch your clients to it, then revoke the old one. A revoked key stops working on the next request. There are no refresh tokens.

Every authentication failure is status 401 with the code invalid_api_key. A missing or malformed header says so in the message; an unknown key, a revoked key and a suspended account all get the same response, so the API never reveals which case it was:

{ "error": { "code": "invalid_api_key", "message": "Invalid API key." } }

The /v1/* endpoints accept only API keys: the dashboard’s sign-in session does not work there.

The API is meant to be called from servers. It sends no CORS headers, so browsers block calls from web pages, and a key in front-end code would be visible to anyone.