Getting started

Authentication

How to send your key and what happens when it is wrong.

All endpoints require a key. Keys start with cmk_, belong to one Coinmico account, and can be created and revoked in the dashboard (up to 5 active keys).

Sending the key

x-api-key: cmk_…
Preferred. Works from servers and browsers; the header is allowed by CORS.
Authorization: Bearer cmk_…
Equivalent, for HTTP clients that only know bearer auth.

When it fails

401 missing_key
No key was sent.
401 invalid_key
The key is unknown or has been revoked. Create a new one in the dashboard.

Keeping it safe

Treat the key like a password: keep it in an environment variable, never commit it, and use a separate key per app so you can revoke one without touching the others. Calling the API directly from a public web page exposes the key to visitors; proxy through your own server instead.

Authentication · Coinmico API Docs