Authentication
All OpenBits API calls require authentication. The primary method is API key authentication via theX-API-Key header.
API Key Authentication
Create an API key from the Dashboard. Keys start withob_live_ and are 32 characters long.
HTTP Header
Pass your key in theX-API-Key header:
CLI Authentication
~/.openbits/config.json. Use openbits logout to clear it.
Organization API Keys
Organizations have their own API keys that draw from the organization’s credit pool instead of your personal balance. To create an org key:- Go to Dashboard > Organizations > [Org Name] > API Keys
- Click Create Key
- Use the org key the same way as a personal key
Key Management
Listing Keys
Revoking Keys
401 Unauthorized immediately. This cannot be undone.
Email Verification
Gateway API calls (e.g., Twitter, Wallet endpoints) require a verified email address. If your email is not verified, you’ll receive a403 Forbidden with error code EMAIL_NOT_VERIFIED.
Verify your email from Dashboard > Settings.
Security Best Practices
- Rotate keys regularly from the dashboard
- Use separate keys for development and production
- Use organization keys for team projects so individuals don’t share personal keys
- Revoke keys immediately if compromised