Skip to main content

Authentication

All OpenBits API calls require authentication. The primary method is API key authentication via the X-API-Key header.

API Key Authentication

Create an API key from the Dashboard. Keys start with ob_live_ and are 32 characters long.

HTTP Header

Pass your key in the X-API-Key header:

CLI Authentication

The CLI stores your key locally in ~/.openbits/config.json. Use openbits logout to clear it.

Organization API Keys

Organizations have their own API keys that draw from the organization’s credit pool instead of your personal balance. To create an org key:
  1. Go to Dashboard > Organizations > [Org Name] > API Keys
  2. Click Create Key
  3. Use the org key the same way as a personal key
Org keys are scoped to the organization — they cannot access personal resources.

Key Management

Listing Keys

Revoking Keys

Revoked keys return 401 Unauthorized immediately. This cannot be undone.

Email Verification

Gateway API calls (e.g., Twitter, Wallet endpoints) require a verified email address. If your email is not verified, you’ll receive a 403 Forbidden with error code EMAIL_NOT_VERIFIED. Verify your email from Dashboard > Settings.

Security Best Practices

Never commit API keys to version control. Use environment variables or secret managers.
  • Rotate keys regularly from the dashboard
  • Use separate keys for development and production
  • Use organization keys for team projects so individuals don’t share personal keys
  • Revoke keys immediately if compromised