Skip to main content

Authentication

Send your API key in the x-api-key request header:

GET /masterdata/getContacts HTTP/1.1
Host: <base URL host>
x-api-key: 4f2a...c91e
ItemDetail
Headerx-api-key: <your key> — the only supported method.
Query parameter?apiKey=<your key> is not accepted. A request authenticated this way returns 401.
Key format64 hexadecimal characters.
ScopeOne key belongs to exactly one business.
ExpiryKeys do not expire. They stop working when you disable or delete them.

Keep keys secret. Never put a key in client-side code (browser JavaScript, mobile apps), public repositories, screenshots or chat messages. Call the API from a server you control. The full key value is shown only once, at creation — myBooksAi cannot display it again afterward. If a key may have been exposed, disable it in Settings > API Keys — requests using it fail immediately — and create a replacement.

If the key is missing, wrong, disabled, or the key's role is not allowed to call the endpoint, the API responds 401 Unauthorized (see Errors).