Getting started
Authentication
How to send your key and what happens when it is wrong.
All endpoints require a key. Keys start with cmk_, belong to one Coinmico account, and can be created and revoked in the dashboard (up to 5 active keys).
Sending the key
x-api-key: cmk_…
Preferred. Works from servers and browsers; the header is allowed by CORS.
Authorization: Bearer cmk_…
Equivalent, for HTTP clients that only know bearer auth.
When it fails
401 missing_key
No key was sent.
401 invalid_key
The key is unknown or has been revoked. Create a new one in the dashboard.
Keeping it safe
Treat the key like a password: keep it in an environment variable, never commit it, and use a separate key per app so you can revoke one without touching the others. Calling the API directly from a public web page exposes the key to visitors; proxy through your own server instead.
