Get started
Authentication
Send your key in the x-api-key header (Authorization: Bearer <key> also works).
Most read endpoints work without a key at a lower rate limit and a shorter history window. /rates/history, webhook management, and /me require one. A key that is present but invalid, revoked or expired is always rejected — it is never silently downgraded to anonymous.