Sending the key
Send the key in theAuthorization header. The Bearer prefix is optional.
Scopes
Each key carries scopes, which decide what it can do. A key with full access covers every scope, including the ones added later. A call to an endpoint outside the key’s scopes answers403 MISSING_SCOPE. Scopes can’t be edited on an existing key: create a new key with the scopes you need.
Each endpoint page also names its scope, right below the
Authorization field.
Restricting a key to resources
A key can also be limited to up to 30 applications and databases. A call about any other resource, or to an account-wide endpoint that can’t be narrowed to those resources, answers403 RESOURCE_NOT_ALLOWED. Listing endpoints such as Account Information return only the resources the key covers.
A restricted key can’t carry the blob:read or blob:write scopes, because stored files belong to the account and not to an application. Create one key for your applications and another one for Blob Storage.
Errors
Every other code is in Errors.
Protection against invalid keys
To protect every account, the API temporarily blocks an IP address that insists on API keys that don’t belong to any account, answering429 RATE_LIMITED for a short period. Valid keys in normal use are not affected. If a request gets a 401, don’t retry it in a loop: fix or replace the key.
Next steps
Your first request
Base URL, a first curl call and the response format.
Limits and restrictions
Request budgets per plan and blocked regions.

