Getting started
Authentication
How to send your API key and keep it safe.
Every request must carry your API key. Send it in the Authorization header as a bearer token, or in the X-Api-Key header if your client can't set Authorization.
Headers#
Authorization: Bearer xca_live_…
# or
X-Api-Key: xca_live_…curl -s "https://app.xca.fun/api/v1/new-pairs?limit=5" \
-H "X-Api-Key: $XCA_API_KEY"Key format#
Keys start with xca_live_ followed by a random base58 string. XCA stores only a hash of the key, so a lost key can't be recovered: create a new one.
Keep keys secret#
- Call the API from your server or bot, never from a public web page or mobile app bundle.
- Don't commit keys to repositories; load them from environment variables or a secret manager.
- Use a separate key per project, so you can revoke one without touching the others.
- Revoked keys stop working immediately.
Rotating a key#
Create a new key, deploy it, check that requests succeed, then revoke the old one on the API page.
Authentication errors#
A missing, malformed or revoked key returns 401 unauthorized. A valid key on a plan without API access returns 402 planRequired.
401
{
"error": {
"code": "unauthorized",
"message": "Invalid API key"
}
}