Authentication
Send your API key in the Authorization header of every request:
Authorization: Bearer mdw_live_<random characters>- A key is
mdw_live_followed by 32 lowercase characters (a-z,2-7). Only a hash is stored: the key is shown once, when you create it. - Keys belong to your account, and credits belong to the account, not to a key. Revoking or replacing a key never changes your balance.
- An account can have up to 10 active keys. Create, rename and revoke them in the dashboard under API keys.
GET /v1/healthis the only endpoint without authentication.
Rotating a key
Section titled “Rotating a key”Create a new key, switch your clients to it, then revoke the old one. A revoked key stops working on the next request. There are no refresh tokens.
Failed authentication
Section titled “Failed authentication”Every authentication failure is status 401 with the code invalid_api_key. A missing or malformed header says so in the message; an unknown key, a revoked key and a suspended account all get the same response, so the API never reveals which case it was:
{ "error": { "code": "invalid_api_key", "message": "Invalid API key." } }The /v1/* endpoints accept only API keys: the dashboard’s sign-in session does not work there.
The API is meant to be called from servers. It sends no CORS headers, so browsers block calls from web pages, and a key in front-end code would be visible to anyone.