Authentication and API keys
Every request to the Motorbay API needs an API key. There is nothing else to set up: no OAuth, no tokens to refresh.
Send the key in one header
curl -H "X-Api-Key: $MOTORBAY_API_KEY" \
"https://api.motorbay.app/v1/dataset"
The key goes in the X-Api-Key header and nowhere else. Keys are not accepted in the query string, where they end up in logs and browser history. A request with the key in the query string and no header gets 401 with the code ApiKeyMissing.
What a key looks like
- Production keys start with
mbk_live_. Keys from a test environment start withmbk_test_. - After the prefix come 43 characters: letters, digits,
-and_. - In samples we write
mbk_test_…or$MOTORBAY_API_KEY. Never paste a real key into an issue, a support email or a screenshot.
A key from one environment doesn't work in the other.
Create a key
- Confirm your email. You can't create a key before you do.
- Choose a plan or start the free trial on Pricing.
- On the dashboard, choose Create key. Give it a name, and an expiry date if you want one.
The key is shown once, when you create it. We store only a hash of it, so we can't show it again or recover it. If you lose a key, create a new one and delete the old one.
Delete or expire a key
Delete a key on the dashboard when you no longer need it, or when it may have leaked. Requests with a deleted key are refused from then on with 401 and the code ApiKeyInvalid. A key that has passed its expiry date is refused the same way.
To rotate a key without downtime: create a new key, deploy it, then delete the old one.
Keep keys on your server
Call the API from your server, not from a browser or a mobile app. Any script on a web page can read a key that page holds, and anyone can extract a key from an app.
Which errors mean what
| Status | Code | Meaning |
|---|---|---|
| 401 | ApiKeyMissing |
No X-Api-Key header |
| 401 | ApiKeyInvalid |
The key is unknown, deleted, expired, or from the other environment |
| 402 | PaymentRequired |
The key's account has no active plan or trial |
See Errors for the full list.