Authentication
The Backoffice API authenticates requests with an API key made up of two values: a key ID and a key value. Each key is scoped to a single tenant in a single environment and cannot be used for any other tenant. Our team provisions your key and delivers it to you securely.
Sandbox and production keys
Sandbox and production are separate environments, each with its own key. Your sandbox key is issued during the implementation process. Once you certify your integration, production keys are granted.
How you receive your key
Our team grants sandbox access. Once your test environment is set up, you receive:
- Your sandbox credentials
- API keys for your test environment
When you are ready to go live, your production credentials and configuration are provisioned the same way.
Your API key
Your key has two values:
| Value | Description |
|---|---|
| Key ID | Identifies the key |
| Key value | The secret paired with the key ID |
Store your key value immediatelyStore both values in a secure, server-side location as soon as you receive them. Key values cannot be recovered, so a lost value means a new key. Keys do not expire.
Authenticating your requests
Backoffice endpoints expect both values in the request headers. Pass the values as:
| Header | Value |
|---|---|
X-AuthenticationKeyId | Your key ID |
X-AuthenticationKeyValue | Your key value |
{
"X-AuthenticationKeyId": "YOUR_KEY_ID",
"X-AuthenticationKeyValue": "YOUR_KEY_VALUE"
}Securing your key
Treat your key value like a password.
Never expose your key value
- Store it in a secrets manager or an environment variable. Never hardcode it in source code.
- Never expose it in client-side code, mobile applications, or browser requests.
- Keep it out of logs, error messages, and URL query strings.
If you think a key value has been exposed, contact us on the Customer Support Portal.
Managing your keys
You can have multiple keys active at the same time. To add, rotate, or revoke a key, contact us on the Customer Support Portal.
Add a key
Generate a new key to support additional integrations, environments, or applications without disrupting your existing keys.
Useful when onboarding a new system or separating access by use case.
Rotate a key
Replace an existing key with a new one while retiring the old one.
Teams typically do this on a regular schedule as a security best practice, or after a key may have been exposed.
Revoke a key
Permanently disable a key that is no longer needed.
Commonly done when decommissioning an integration, offboarding a team member with key access, or responding to a suspected compromise.
NOTE: Infinicept reserves the right to revoke a client's API key at our discretion in cases of misuse, security concerns, or other special circumstances, in order to protect the integrity of our systems and services.
Errors
Requests with a missing, misplaced, or incorrect value return a 401 Unauthorized. The response body is empty, so check the API key headers you sent and confirm the key is active for the tenant you are calling. For the full list of status codes and response bodies, see Backoffice API Status Codes.
Support
Have a question? Contact us on the Customer Support Portal.
Learn about updates in our Changelog.
Updated 23 days ago
