Authorization header using the Bearer scheme. The API validates the key on every request, checks that it has the required scope for the endpoint being called, and — if IP allowlisting is enabled on your key — verifies the originating IP address. Without a valid, in-scope key, the request is rejected before any logic runs.
Getting an API key
1
Open your account settings
Click your avatar in the top-right corner of the dashboard and select Settings.
2
Navigate to API Keys
Select the API Keys tab in the left sidebar of the Settings page.
3
Create a new key
Click Generate New Key, give it a descriptive name, choose the scopes it needs, and optionally restrict it to specific IP addresses.
4
Copy and store the key securely
The secret value is shown only once. Copy it into a password manager or secrets vault before closing the dialog.
Making authenticated requests
Pass your API key as a Bearer token in theAuthorization header of every request:
Store your API key in an environment variable (for example,
BBA_API_KEY) rather than hardcoding it in your source files. Read it at runtime with process.env.BBA_API_KEY (Node.js) or os.environ["BBA_API_KEY"] (Python).Key scopes
When you generate a key you assign it one or more scopes that control which endpoints it can call:
If you call an endpoint with a key that lacks the required scope, the API returns a
403 Insufficient Scope error. Always use the most restrictive scope that your integration actually needs.
Authentication errors
Managing API keys programmatically
In addition to creating and revoking keys in the dashboard, you can manage them through the API itself. Both endpoints require an existing key with theall scope.
GET /auth/api-keys
Returns a list of all API keys on your account (secret values are never returned — only metadata).string
Unique identifier for the API key.
string
Human-readable name you set when creating the key.
array
List of permission scopes assigned to this key.
array
IP addresses or CIDR ranges allowed to use this key. Empty array means no restriction.
string
ISO 8601 timestamp of when the key was created.
string
ISO 8601 timestamp of the most recent authenticated request.
null if never used.POST /auth/api-keys
Creates a new API key. The secret value is returned only in this response — store it immediately.string
required
A descriptive name for the key (e.g.,
"Trading bot", "Alerts automation").array
required
Array of permission scopes:
read, trade, alerts, or all.array
Optional list of IPv4/IPv6 addresses or CIDR ranges. Omit to allow requests from any IP.