Get Started

Authentication

Authenticate every request with a Bearer API key.

Bearer tokens

All authenticated API requests use:

Header
Authorization: Bearer YOUR_API_KEY

Example:

Header
Authorization: Bearer pk_live_xxxxxxxxxxxxxxxxx
  • API keys are created from Dashboard → API.
  • One API key can access both services when both permissions are enabled.
  • Access still depends on per-key service permissions.

Correct usage

HTTP
GET /api/v1/ping/ HTTP/1.1
Host: engagegrove.com
Authorization: Bearer YOUR_API_KEY
Accept: application/json

Incorrect usage

Do not put API keys in query strings or request bodies for authentication:

Incorrect
?api_key=YOUR_API_KEY

Query-string authentication is rejected by the API.

Security

Important

Never expose your API key in frontend code, public repositories, or query strings.

  • Never expose API keys publicly.
  • Never commit API keys to GitHub or other repositories.
  • Never place API keys in URLs.
  • Never expose API keys in frontend / browser code.
  • Revoke a key immediately if it may have leaked.