Skip to main content
Every request to the Big Brain Ape API must be authenticated with an API key. You pass your key in the Authorization header using the Bearer scheme. The API validates the key on every request, checks that it has the required scope for the endpoint being called, and — if IP allowlisting is enabled on your key — verifies the originating IP address. Without a valid, in-scope key, the request is rejected before any logic runs.
Never expose your API key in client-side code, public repositories, or anywhere it could be read by a third party. Anyone who obtains your key can take actions on your account up to the permissions granted by that key’s scopes. If a key is compromised, revoke it immediately from the dashboard and generate a new one.

Getting an API key

1

Open your account settings

Click your avatar in the top-right corner of the dashboard and select Settings.
2

Navigate to API Keys

Select the API Keys tab in the left sidebar of the Settings page.
3

Create a new key

Click Generate New Key, give it a descriptive name, choose the scopes it needs, and optionally restrict it to specific IP addresses.
4

Copy and store the key securely

The secret value is shown only once. Copy it into a password manager or secrets vault before closing the dialog.
For a full walkthrough including scope selection and IP allowlisting, see the API Keys security guide.

Making authenticated requests

Pass your API key as a Bearer token in the Authorization header of every request:
The same pattern applies in any language or HTTP client:
Store your API key in an environment variable (for example, BBA_API_KEY) rather than hardcoding it in your source files. Read it at runtime with process.env.BBA_API_KEY (Node.js) or os.environ["BBA_API_KEY"] (Python).

Key scopes

When you generate a key you assign it one or more scopes that control which endpoints it can call: If you call an endpoint with a key that lacks the required scope, the API returns a 403 Insufficient Scope error. Always use the most restrictive scope that your integration actually needs.

Authentication errors

Managing API keys programmatically

In addition to creating and revoking keys in the dashboard, you can manage them through the API itself. Both endpoints require an existing key with the all scope.

GET /auth/api-keys

Returns a list of all API keys on your account (secret values are never returned — only metadata).
Response:
string
Unique identifier for the API key.
string
Human-readable name you set when creating the key.
array
List of permission scopes assigned to this key.
array
IP addresses or CIDR ranges allowed to use this key. Empty array means no restriction.
string
ISO 8601 timestamp of when the key was created.
string
ISO 8601 timestamp of the most recent authenticated request. null if never used.

POST /auth/api-keys

Creates a new API key. The secret value is returned only in this response — store it immediately.
string
required
A descriptive name for the key (e.g., "Trading bot", "Alerts automation").
array
required
Array of permission scopes: read, trade, alerts, or all.
array
Optional list of IPv4/IPv6 addresses or CIDR ranges. Omit to allow requests from any IP.
Response:
The secret field is returned only once in this response. Copy it to a secure location immediately — it cannot be retrieved again. If you lose it, revoke the key and create a new one.