API DOCUMENTATION / AUTHENTICATION
Authentication
Send the source-supported bearer token in the Authorization header and keep credentials server-side.
Bearer API key
The routes use Authorization: Bearer <API_KEY>. Keys follow the format ar_live_<UUIDv4>.<43-character base64url secret>. Authentication verifies a stored digest and key/customer status; the secret itself is not stored.
Example header
Authorization: Bearer <API_KEY>Create keys at api.headcountlabs.com/data/keys and send the full key.
Credential handling
Keep the key in a server-side secret store or protected environment variable. Do not put it in browser code, mobile bundles, URLs, source control, client logs, or analytics events.
Authentication failures
Missing or invalid bearer credentials map to HTTP 401 with WWW-Authenticate: Bearer and a structured error. Use the account page to open signup and login.
Continue in the reference
Check related request behavior before you build.
View route status and methods Discuss API requirements