Skip to main content

API keys and access tokens

Every request to the Spaycial API authenticates with one or more of the following headers.

Api-Key​

Sent in the Api-Key header. It is provided to you by email - see Environments and access.

Authorization (member access token)​

Sent as Authorization: Bearer <token>. Required to access the API on behalf of a member, except for registration. A member's access token is issued by Get an access token.

Registration access token​

Also sent as Authorization: Bearer <token>, but only valid for the registration operations (a member's sign-up flow).

Signature​

Sent in the Signature header. Used to authenticate a request to the API as a service, rather than as a member - see Request signature.

How a member gets their access token​

Once a member is subscribed, they can access different views of their data. Your website first fetches a Spaycial access token for the member from Get an access token. If you have set up an access token validation endpoint, Spaycial verifies the member's external token against it before issuing the access token.