API
Authentication
Authenticate your API requests using API keys
# Authentication > Authenticate your API requests using API keys - Page: https://tbit.app/docs/api/authentication - Base URL: `https://rest-api.tbit.app/v1` - Authentication: `X-API-Key` header with your key on every request (the examples read it from the `TBIT_API_KEY` environment variable) ## Overview The TBit API uses API keys for authentication. Include your API key in the X-API-Key header with every request. ## Getting Your API Key Navigate to Settings > API in the TBit dashboard to reveal your API key. Each agent has a unique API key. ## Usage Include the X-API-Key header in every request: `GET /v1/activities` ```bash curl "https://rest-api.tbit.app/v1/activities" \ -H "X-API-Key: $TBIT_API_KEY" ``` ## Security Best Practices - Never expose your API key in client-side code or public repositories - Use environment variables to store your API key - Rotate your API key if you suspect it has been compromised - Only use HTTPS when making API requests ## Publishable Usage for Catalog Endpoints Exception: for catalog read endpoints (products, categories, carts) the API key acts like a publishable key: it identifies your tenant and meters usage, and catalog data is public. It is safe to use from browser code for those endpoints, just like a Stripe publishable key. ## Authentication Errors | Status | Code | Description | | --- | --- | --- | | `401` | `UNAUTHORIZED` | Missing or invalid API key | | `429` | `RATE_LIMITED` | Rate limit exceeded (100 req/min) |The TBit API uses API keys for authentication. Include your API key in the X-API-Key header with every request.
Navigate to Settings > API in the TBit dashboard to reveal your API key. Each agent has a unique API key.
Include the X-API-Key header in every request:
/v1/activitiescurl "https://rest-api.tbit.app/v1/activities" \
-H "X-API-Key: $TBIT_API_KEY"const response = await fetch('https://rest-api.tbit.app/v1/activities', {
headers: {
'X-API-Key': process.env.TBIT_API_KEY,
},
});
const data = await response.json();import axios from 'axios';
const { data } = await axios.get(
'https://rest-api.tbit.app/v1/activities',
{
headers: {
'X-API-Key': process.env.TBIT_API_KEY,
},
},
);import os
import requests
response = requests.get(
'https://rest-api.tbit.app/v1/activities',
headers={'X-API-Key': os.environ['TBIT_API_KEY']},
)
data = response.json()<?php
$ch = curl_init('https://rest-api.tbit.app/v1/activities');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'X-API-Key: ' . getenv('TBIT_API_KEY'),
],
]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);- Never expose your API key in client-side code or public repositories
- Use environment variables to store your API key
- Rotate your API key if you suspect it has been compromised
- Only use HTTPS when making API requests
Exception: for catalog read endpoints (products, categories, carts) the API key acts like a publishable key: it identifies your tenant and meters usage, and catalog data is public. It is safe to use from browser code for those endpoints, just like a Stripe publishable key.
| Status | Code | Description |
|---|---|---|
401 | UNAUTHORIZED | Missing or invalid API key |
429 | RATE_LIMITED | Rate limit exceeded (100 req/min) |