Authentication
Secure your API requests with Bearer token authentication
Overview
The Ordinal API uses Bearer token authentication. All API requests must include a valid API key in the Authorization header.
Authorization: Bearer ord_XXXXXXXXXXXXXXXX
Generating an API Key
Navigate to Workspace Settings
Go to the API Keys page in your workspace.
Open API Keys Section
Click on the “API Keys” tab in the settings menu.
Create New Key
Click “Create an API Key” and provide a descriptive name for the key.
Copy Your Key
Copy the generated API key immediately. For security reasons, the full key is only shown once.
Making Authenticated Requests
Include your API key in the Authorization header with the Bearer prefix:
curl -X GET "https://app.tryordinal.com/api/v1/workspace" \
-H "Authorization: Bearer ord_XXXXXXXXXXXXXXXX"const response = await fetch('https://app.tryordinal.com/api/v1/workspace', {
headers: {
'Authorization': 'Bearer ord_XXXXXXXXXXXXXXXX'
}
});import requests
response = requests.get(
'https://app.tryordinal.com/api/v1/workspace',
headers={'Authorization': 'Bearer ord_XXXXXXXXXXXXXXXX'}
)Authentication Errors
When authentication fails, the API returns specific error codes to help you diagnose the issue.
Missing Token
If no authorization header is provided:
{
"code": "UNAUTHORIZED",
"message": "Missing bearer token"
}
Status Code: 401 Unauthorized
Invalid or Not Found
If the API key is invalid or doesn’t exist:
{
"code": "UNAUTHORIZED",
"message": "Invalid or unauthorized API key"
}
Status Code: 401 Unauthorized
Rate Limited
If you’ve exceeded the rate limit for your workspace:
{
"code": "TOO_MANY_REQUESTS",
"message": "Rate limit of 100 requests per 60s exceeded. Quota resets in 45 seconds"
}
Status Code: 429 Too Many Requests
Revoked Key
If the API key has been revoked:
{
"code": "FORBIDDEN",
"message": "API key was revoked 2 days ago"
}
Status Code: 403 Forbidden
Expired Key
If the API key has expired:
{
"code": "FORBIDDEN",
"message": "API key is expired"
}
Status Code: 403 Forbidden
Disabled Key
If the API key has been disabled:
{
"code": "FORBIDDEN",
"message": "Invalid or unauthorized API key"
}
Status Code: 403 Forbidden
Insufficient Permissions
If the API key doesn’t have the required permissions:
{
"code": "FORBIDDEN",
"message": "Insufficient permissions"
}
Status Code: 403 Forbidden
Insufficient Credits
If your account has run out of API credits:
{
"code": "FORBIDDEN",
"message": "Insufficient credits"
}
Status Code: 403 Forbidden
Usage Exceeded
If you’ve exceeded your usage quota:
{
"code": "FORBIDDEN",
"message": "Usage exceeded"
}
Status Code: 403 Forbidden
Error Code Reference
| Error Code | HTTP Status | Description |
|---|---|---|
UNAUTHORIZED |
401 | Missing or invalid API key |
TOO_MANY_REQUESTS |
429 | Rate limit exceeded |
FORBIDDEN |
403 | Key revoked, expired, disabled, or insufficient permissions |
Best Practices
Use Environment Variables
Store your API key in environment variables rather than hardcoding it in your application.
export ORDINAL_API_KEY="ord_XXXXXXXXXXXXXXXX"const apiKey = process.env.ORDINAL_API_KEY;Rotate Keys Regularly
Periodically rotate your API keys to minimize the impact of potential key exposure.
Monitor Key Usage
Regularly review your API key usage in the dashboard to detect any unusual activity.
Revoke Compromised Keys
If you suspect an API key has been compromised, revoke it immediately and generate a new one.
Managing API Keys
Viewing Keys
You can view all your API keys in the workspace settings. Each key shows:
- Name and description
- Creation date
- Last used timestamp
Revoking Keys
To revoke an API key:
- Navigate to workspace settings
- Find the key you want to revoke
- Click the
...button and select “Revoke” - Confirm the action