xcaDocs
Getting started

Authentication

How to send your API key and keep it safe.

Every request must carry your API key. Send it in the Authorization header as a bearer token, or in the X-Api-Key header if your client can't set Authorization.

Headers#

Authorization: Bearer xca_live_…
# or
X-Api-Key: xca_live_…
curl -s "https://app.xca.fun/api/v1/new-pairs?limit=5" \
  -H "X-Api-Key: $XCA_API_KEY"

Key format#

Keys start with xca_live_ followed by a random base58 string. XCA stores only a hash of the key, so a lost key can't be recovered: create a new one.

Keep keys secret#

  • Call the API from your server or bot, never from a public web page or mobile app bundle.
  • Don't commit keys to repositories; load them from environment variables or a secret manager.
  • Use a separate key per project, so you can revoke one without touching the others.
  • Revoked keys stop working immediately.

Rotating a key#

Create a new key, deploy it, check that requests succeed, then revoke the old one on the API page.

Authentication errors#

A missing, malformed or revoked key returns 401 unauthorized. A valid key on a plan without API access returns 402 planRequired.

401
{
  "error": {
    "code": "unauthorized",
    "message": "Invalid API key"
  }
}