Authentication
There is no API key header. A request authenticates by signing its own body: you compute an HMAC-SHA1 over the request fields with your project’s auth secret and send it alongside the data. The server recomputes the signature and rejects the request when it doesn’t match.Your credentials
The project page in the dashboard shows two values:The auth secret is a bearer secret
Anyone holding it can speak for your project: check keys against it and verify (or forge client-side) signed responses. It cannot create, revoke, or modify keys — that requires your dashboard session — but treat it like a password. This is the same model Luarmor uses: the secret ships inside your obfuscated script. Obfuscation is what protects it, so embed it in the script config before obfuscating, never fetch it at runtime. If a secret leaks, rotate it in the dashboard. Rotating invalidates every deployed copy of your script until you ship an update — worth doing anyway if you suspect extraction.How signing works
The request signature is lowercase-hex HMAC-SHA1 over the fields joined with|:
signature field. The full request contract is on key/check; verifying the response is covered in Signature verification.
Rate limits
Exceeding it returns
429 with retry_after (seconds).