Hexascore

Authentication

Every request is authenticated with a secret API key sent as a Bearer token.

Bearer token

Send the key in the Authorization header. Keys look like hx_live_ followed by 32 letters and digits. Query-string keys are not accepted, so keys never end up in access logs or browser history.

HTTP
GET /v1/movies?sort=-score HTTP/1.1
Host: api.hexascore.com
Authorization: Bearer hx_live_0123456789ABCDEFGHIJabcdefghij

A missing, malformed, unknown or revoked key returns 401 with code: "unauthorized" and a WWW-Authenticate: Bearer header.

Managing keys

  • Create and revoke keys at /profile/api (verified email required, up to 5 active keys).
  • The full key is shown once. Only a SHA-256 hash is stored; we cannot recover it for you.
  • Revocation is immediate. Rotate by creating a new key, deploying it, then revoking the old one.
  • All keys of an account share the same plan, quota and per-second rate limit.

Keep keys secret