Authorization header:
Get your first key
1
Subscribe to Pro or Max
Choose a plan on Pricing.
2
Create a key
Open Developers and click Create key. Copy the full key; it is shown once.
3
Save it on your server
Read the key from your environment or a secret manager. Use the environment variable
OXINSIDER_API_KEY with the official clients.Choose a credential
Live API keys start with
oxi_sk_live_, followed by 64 hex characters, for 76 characters total. OAuth access tokens start with oxi_at_, followed by 64 hex characters; their oxi_rt_ refresh tokens last 30 days.
An account can have multiple active default keys and up to 10 named integrations. Creating a default key keeps your existing keys valid. During rotation, an integration can temporarily have 2 live keys; the server stores key hashes, rather than the original secrets.
OAuth supports authorization code with PKCE and device authorization for a headless agent or CLI. Follow the OAuth instructions to build either flow.
Set scopes
Default keys carry all 4 scopes. Integration keys and OAuth tokens must include the scope required by the endpoint:
A missing scope returns
403 insufficient_scope. The WWW-Authenticate header names the scope you need.
Keep credentials private
Give each integration only the scopes it needs. For an MCP client, use its environment configuration or a secret store rather than including the secret in its arguments.
Keys in URLs are also refused. On an authenticated endpoint,
?token= returns 401 invalid_api_key with error.reason set to api_key_in_query; move it to the Bearer header.
Endpoints that need no credential
Public API endpoints ignore a supplied credential and a
?token= parameter. Other data endpoints, Remote MCP tools/call, and the live event stream require a valid credential and active Pro or Max access.
Manage your live API keys
Click Create key on Developers to add a key. Each key stays valid until you revoke it. Click Revoke beside a key to stop only that key; your other keys keep working. These account-management endpoints require a signed-in Pro or Max website session. A developer API key does not authenticate them.
To replace a key, create a new one, update every consumer that uses the old key, and revoke the old key. If a key appears in a log, commit, or shared terminal, revoke it immediately. Requests using a revoked key return
401 invalid_api_key.
The legacy POST /api/keys/regenerate endpoint still revokes every active default key and creates 1 replacement. Use it only when you intend to replace all default keys. Named integration keys and OAuth tokens are unaffected.
Manage an integration key
These account-management endpoints require a signed-in Pro or Max website session. A developer API key does not authenticate them.
For example, this creation body permits API reads and usage inspection, but excludes webhook management and exports:
integration_id. Rotation returns a new key and overlap_ends_at; switch consumers before that time.
The rotation overlap lasts 15 minutes. A 409 means a prior overlap is still active; wait for it to end or revoke the integration. Revocation stops both keys immediately.
Listing returns prefixes, scopes, expiry, last use, revocation, and monthly counts without exposing secrets. The default page has at most 100 rows, the maximum is 200, and next_before_id becomes the next request’s before_id. Usage totals update every 5 minutes.