Skip to main content

API Key Authentication

All requests require an API key passed in the X-API-Key header:
API keys are prefixed with sk_ (secret key). Keep your key secure — do not expose it in client-side code, public repositories, or browser requests.
Requests without a valid API key receive a 401 Unauthorized response.

Entity Scoping

Every API key is associated with an entity level in the hierarchy: Partner, Merchant, or Branch. Data access is automatically restricted based on your key’s level.
Entity scoping is applied automatically — you don’t need to add any special filters. A merchant-level key will never see another merchant’s data, even if you try to filter by their merchant_id.

Error Responses

401 Unauthorized

Returned when the API key is missing, invalid, or expired:

403 Forbidden

Returned when the API key is valid but doesn’t have permission for the requested resource:

Security Best Practices

Never include API keys in frontend code, mobile apps, or public repositories. Make API calls from your backend server.
Store API keys in environment variables, not in source code:
Contact support@moduluslabs.io to rotate your API key if you suspect it has been compromised.
Request a merchant-level or branch-level key if you don’t need partner-wide access. Least privilege reduces the impact of key exposure.

What’s Next?

Quickstart

Make your first API call

Filtering & Sorting

Learn all available query parameters