Authentication¶
The API uses a member API key on a service account. Create the account, organization, service account, and key at e10s.io. Send the key on every request:
Host: https://api.e10s.io. Paths do not include an organization id. The key is the organization.
Member keys belong to one organization. They are scoped. They are not your subscribers’ credentials.
Danger
Keep member API keys on servers only. Never ship them in browsers, mobile apps, or other untrusted clients.
Mint a key¶
On the service account, Create key. How to mint: Console.
| Label | What it allows |
|---|---|
check |
GET entitlements + POST check |
catalog:read |
features, plans |
catalog:write |
features, plans |
subscribers:read |
subscribers, subscriptions, overrides |
subscribers:write |
subscribers, subscriptions, overrides |
org:read |
org, members, invites, keys, webhook |
org:write |
org, members, invites, keys, webhook |
New keys default to check. Full access (omit scopes) is unrestricted. Write does not include read.
Webhook config is org:read / org:write in the console. Incoming POSTs are HMAC — Webhooks.
Rotate keys at e10s.io: create a new key, deploy it, revoke the old one. The plaintext secret is shown once at creation.
What not to send¶
Do not send tokens for your subscribers’ end users to e10s. Authenticate those users in your app, then call e10s with your member key and that customer’s subscriber id.
Failures¶
| HTTP | Meaning |
|---|---|
| 401 | Missing, invalid, or revoked credential |
| 403 | Authenticated, but the key is missing a required scope. See Errors. |
| 404 | Unknown id |
| 429 | Too many requests on GET entitlements + POST check. See Errors. |
A check key hitting POST /org/features is 403, not 401. Do not treat that as a broken key.