Skip to main content

Authentication

There is no API key header. A request authenticates by signing its own body: you compute an HMAC-SHA1 over the request fields with your project’s auth secret and send it alongside the data. The server recomputes the signature and rejects the request when it doesn’t match.

Your credentials

The project page in the dashboard shows two values:

The auth secret is a bearer secret

Anyone holding it can speak for your project: check keys against it and verify (or forge client-side) signed responses. It cannot create, revoke, or modify keys — that requires your dashboard session — but treat it like a password. This is the same model Luarmor uses: the secret ships inside your obfuscated script. Obfuscation is what protects it, so embed it in the script config before obfuscating, never fetch it at runtime. If a secret leaks, rotate it in the dashboard. Rotating invalidates every deployed copy of your script until you ship an update — worth doing anyway if you suspect extraction.

How signing works

The request signature is lowercase-hex HMAC-SHA1 over the fields joined with |:
Send it in the body’s signature field. The full request contract is on key/check; verifying the response is covered in Signature verification.

Rate limits

Exceeding it returns 429 with retry_after (seconds).