API keys
All API requests are authenticated using a Secret Key passed in the x-api-key header. Each SaaS product in your Anderro account has its own unique API key pair.
All /api/v1/* endpointsKey format
| Key type | Prefix | Usage |
|---|---|---|
| Secret Key | sk_ | Live server-side API calls |
| Test Secret Key | sk_test_ | Selects sandbox mode on tracking endpoints only |
sk_test_ keys do not authenticate /api/v1 requests. Use your product's live secret key for the management API. Test keys only select sandbox on the tracking endpoints, including POST /events.
Security
Your secret key grants full access to manage affiliates in your program. Never expose it in client-side code, Git repositories, or logs.
Using your API key
Include the key in the x-api-key header with every request:
curl -X POST https://anderro.com/api/v1/affiliates \
-H "Content-Type: application/json" \
-H "x-api-key: sk_your_secret_key" \
-d '{"email": "[email protected]"}'
Finding your key
- Log in to anderro.com
- Go to Products and select your SaaS product
- Open the Integration tab
- Your Secret Key is shown there - click to copy
Regenerating keys
If your key is compromised, you can regenerate it from the Integration tab. This immediately invalidates the old key - all requests using the old key will return 401.
Error responses
| Status | Error | Meaning |
|---|---|---|
401 | Missing x-api-key header | No API key was provided |
401 | Invalid API key format | Key doesn't start with sk_ |
401 | Invalid or revoked API key | Key doesn't match any active product |