Skip to content

Authentication

The API uses a member API key on a service account. Create the account, organization, service account, and key at e10s.io. Send the key on every request:

X-API-Key: e10s-mk-1-…

Host: https://api.e10s.io. Paths do not include an organization id. The key is the organization.

Member keys belong to one organization. They are scoped. They are not your subscribers’ credentials.

Danger

Keep member API keys on servers only. Never ship them in browsers, mobile apps, or other untrusted clients.

Mint a key

On the service account, Create key. How to mint: Console.

Label What it allows
check GET entitlements + POST check
catalog:read features, plans
catalog:write features, plans
subscribers:read subscribers, subscriptions, overrides
subscribers:write subscribers, subscriptions, overrides
org:read org, members, invites, keys, webhook
org:write org, members, invites, keys, webhook

New keys default to check. Full access (omit scopes) is unrestricted. Write does not include read.

Webhook config is org:read / org:write in the console. Incoming POSTs are HMAC — Webhooks.

Rotate keys at e10s.io: create a new key, deploy it, revoke the old one. The plaintext secret is shown once at creation.

What not to send

Do not send tokens for your subscribers’ end users to e10s. Authenticate those users in your app, then call e10s with your member key and that customer’s subscriber id.

Failures

HTTP Meaning
401 Missing, invalid, or revoked credential
403 Authenticated, but the key is missing a required scope. See Errors.
404 Unknown id
429 Too many requests on GET entitlements + POST check. See Errors.

A check key hitting POST /org/features is 403, not 401. Do not treat that as a broken key.