Authentication
Site integrations use your String API key, the same one you use for Web Access.
Site integrations use the same API key as the rest of Web Access. Send it as a Bearer token in the Authorization
header of every POST to an action:
Authorization: Bearer YOUR_API_KEYThe examples on the catalog pages read the key from an environment variable, $STRING_API_KEY. Set it
once in your shell and paste the examples as they are:
export STRING_API_KEY="your key"The GET routes that describe the integrations (the catalog and the schemas) are public and need no key. See
Making a request.
Getting a key
- Sign in to the String dashboard and open Settings.
- Under Your API keys, select Generate key.
- Copy the key from the dialog. It's shown once; after you close the dialog it can't be viewed again.
An organization can hold up to 100 active keys. Every key spends the same organization balance, so a separate key per application lets you revoke one without affecting the others.
How your key is used
The integrations service holds no key of its own. When you call an action, it forwards your key on every request the
action makes to /v1/fetch. Web Access checks the key, your balance, your access rules and your
rate limit on each of those requests, exactly as it would for a request you sent yourself.
That has two consequences:
- Anything your key can't do through
/v1/fetch, it can't do through an integration either. - Each request an action makes is billed to your organization, and counts towards your rate limit. One call can make several requests; the response lists them.
Errors
When Web Access refuses your key, the whole call stops and you get Web Access's own status and body, unchanged. There is no partial result, because the same refusal would apply to every remaining request.
| Status | Meaning | What to do |
|---|---|---|
401 Unauthorized | The Authorization header is missing or malformed, or the key is invalid or revoked. | Check the header is Bearer followed by an active key. |
402 Payment Required | The key is valid but your organization's balance can't cover the request. | Add funds under Usage & Plans, then retry. |
403 Forbidden | The key is valid but your organization isn't allowed to make a request the action needs. | Read the body; see Access control & KYC. |
429 Too Many Requests | Your organization is over its rate limit. | Wait for Retry-After when present, then retry with backoff. |
{ "error": "Invalid API key" }The full list of statuses an action can return is in Responses & errors.