// guide
Authentication
Every request carries one API key. The key alone decides which marketplace you reach, and whether it is test or live.
Send the key
curl https://api.marketsdk.com/v1/marketplace \
-H "Authorization: Bearer msk_test_sk_..."A request with no key, or a key we do not know, gets 401 with api_key_missing or api_key_invalid. We keep only a hash of each key, so we cannot show one again: copy it when you create it.
Two kinds of key
| kind | starts | use it from | can call |
|---|---|---|---|
| secret | msk_test_sk_ / msk_live_sk_ | your server only | everything |
| publishable | msk_test_pk_ / msk_live_pk_ | your web pages | published listings, search, and public seller profiles |
- A secret key sent from a browser is refused with
secret_key_in_browser, so a key pasted into front-end code fails at once instead of leaking quietly. Roll any key that reached a browser. - A publishable key calling anything else gets 403
publishable_key_not_allowed. The API reference marks the endpoints it may call. - List the origins your pages run on under marketplace, such as
https://shop.example.com. A publishable key used from any other origin gets 403origin_not_allowed. With no origins listed, any origin may use it.
Test keys and live keys
msk_test_ keys reach your test marketplace and msk_live_ keys your live one. They are separate marketplaces: an id from one is not found in the other, and nothing you do in test reaches live. See test and live.
Rotate and revoke
- Name each key after where it runs, so the dashboard's last used time tells you which system still uses it.
- Rotate makes a new key with the same name and kind. The old one can keep working for up to 7 days while you deploy the new one, or stop at once.
- Revoke stops a key at once. Do this for a key that leaked.
- Keys are prefixed so secret scanners can spot them. If one turns up in a repository, revoke it.