API DOCUMENTATION / AUTHENTICATION

Authentication

Send the source-supported bearer token in the Authorization header and keep credentials server-side.

Bearer API key

The routes use Authorization: Bearer <API_KEY>. Keys follow the format ar_live_<UUIDv4>.<43-character base64url secret>. Authentication verifies a stored digest and key/customer status; the secret itself is not stored.

Example header

Authorization: Bearer <API_KEY>

Create keys at api.headcountlabs.com/data/keys and send the full key.

Credential handling

Keep the key in a server-side secret store or protected environment variable. Do not put it in browser code, mobile bundles, URLs, source control, client logs, or analytics events.

Authentication failures

Missing or invalid bearer credentials map to HTTP 401 with WWW-Authenticate: Bearer and a structured error. Use the account page to open signup and login.

Continue in the reference

Check related request behavior before you build.

View route status and methods Discuss API requirements
All API documentation