Skip to content

Authentication

API keys, live and test keys, keeping them safe and replacing them.

API keys

Every request to the Data API carries an API key as a bearer token:

Shell
curl -H "Authorization: Bearer prc_live_Ab3dE…" https://pricana.io/api/v1/datasets

Create keys in the portal under API. Every member of your team can; each key belongs to your company, not to the person who made it, and keeps working when that person leaves. The portal lists every key with when it was last used and how many calls it made today and this month.

A key is shown once, when it is made. Pricana keeps only a hash of it: if it is lost, make a new one.

Live and test keys

PrefixReads
prc_live_…your datasets, as your plan shows them
prc_test_…only the sample datasets: for building and testing your integration

Both count against the same limits (Limits and quotas).

Keep keys safe

  • Store keys like passwords: in environment variables or a secret manager, never in code, a repository or a browser.
  • Use one key per program or server, named after it ("Nightly import"), so you can replace one without touching the others.
  • Call the API from your servers only. A key in a web page or a mobile app can be read by anyone who uses it.

Replace a key

  1. Create a new key in the portal.
  2. Put it into your program and deploy.
  3. Check under API that the old key is no longer used (last used), then revoke it.

A revoked key stops working at once and answers 401. If a key may have leaked, revoke it first and make the new one second.

Errors

StatusMeans
401no key, or one that is wrong, revoked or of the old format (sk_scr_…)
403the key's company account is no longer active

Both bodies say what is wrong and link to Errors.