Authentication

The Backoffice API authenticates requests with an API key made up of two values: a key ID and a key value. Each key is scoped to a single tenant in a single environment and cannot be used for any other tenant. Our team provisions your key and delivers it to you securely.

Sandbox and production keys

Sandbox and production are separate environments, each with its own key. Your sandbox key is issued during the implementation process. Once you certify your integration, production keys are granted.

How you receive your key

Our team grants sandbox access. Once your test environment is set up, you receive:

  • Your sandbox credentials
  • API keys for your test environment

When you are ready to go live, your production credentials and configuration are provisioned the same way.

Your API key

Your key has two values:

ValueDescription
Key IDIdentifies the key
Key valueThe secret paired with the key ID
🚧

Store your key value immediately

Store both values in a secure, server-side location as soon as you receive them. Key values cannot be recovered, so a lost value means a new key. Keys do not expire.

Authenticating your requests

Backoffice endpoints expect both values in the request headers. Pass the values as:

HeaderValue
X-AuthenticationKeyIdYour key ID
X-AuthenticationKeyValueYour key value
{
  "X-AuthenticationKeyId": "YOUR_KEY_ID",
  "X-AuthenticationKeyValue": "YOUR_KEY_VALUE"
}

Securing your key

Treat your key value like a password.

❗️

Never expose your key value

  • Store it in a secrets manager or an environment variable. Never hardcode it in source code.
  • Never expose it in client-side code, mobile applications, or browser requests.
  • Keep it out of logs, error messages, and URL query strings.

If you think a key value has been exposed, contact us on the Customer Support Portal.

Managing your keys

You can have multiple keys active at the same time. To add, rotate, or revoke a key, contact us on the Customer Support Portal.

NOTE: Infinicept reserves the right to revoke a client's API key at our discretion in cases of misuse, security concerns, or other special circumstances, in order to protect the integrity of our systems and services.

Errors

Requests with a missing, misplaced, or incorrect value return a 401 Unauthorized. The response body is empty, so check the API key headers you sent and confirm the key is active for the tenant you are calling. For the full list of status codes and response bodies, see Backoffice API Status Codes.


Support

Have a question? Contact us on the Customer Support Portal.

Learn about updates in our Changelog.






Did this page help you?