Header
Send your key in theX-API-Key header:
Key formats
Rangler keys are environment-specific. A live key cannot be used against sandbox, and a sandbox key cannot be used against live.
Where keys come from
Generate and revoke keys in portal.rangler.co. The portal is the only supported human workflow for key management in the current customer offering.Access model
- API keys belong to organizations, not individual developers
- usage is metered at the organization level
- keys should be stored in your own secret manager
- revoke unused keys instead of rotating shared credentials informally
- live keys require an approved paid organization; trial organizations are sandbox-only
Scopes
Choose the smallest set of product scopes the integration needs:
The
admin scope is reserved for Rangler operations and should not be assigned to customer keys.
A paid plan is checked separately from the key scope. For example, a data key from a trial organization cannot read paid statement financials.
Company-email access
Portal access is restricted to company emails. Personal mailbox domains are not accepted for customer onboarding.Authentication failures
Rangler returns401 Unauthorized when:
- the key is missing
- the key is invalid
- the key has been revoked
- the key is expired
- the key is used against the wrong environment
403 Forbidden when the key is valid but its organization, plan, market entitlement, or product scope does not permit the requested operation.
See Errors for the full response shape.