Authentication

Every endpoint except the item icons needs a key, sent in the Authorization header:

GET /v1/recipes/milk-stout HTTP/1.1
Authorization: Bearer td_live_<32 letters and digits>_<6-character checksum>

The last six characters are a checksum, so a mistyped key is refused at once with 401.

Never in the URL

A request with the key in the query string (?key=, ?token=, ?api_key=…) is refused with 400 token-in-url, even when the key is valid. URLs end up in server logs, browser history and Referer headers.

Keep the key on a server

  • Read it from an environment variable or a secret manager, never from your source code.
  • Do not ship it in a website, a mobile app or a desktop app: anyone can extract it from there. Call the API from your own backend and cache the answers.
  • Do not commit it. If it reaches a public repository, revoke it at once.

Revoking

Revoke a key in the dashboard. It stops working within a minute everywhere. You can have up to three active keys, which lets you rotate one without downtime: create the new key, deploy it, then revoke the old one.

Icons

Item sprites are plain images at /v1/icons/{item_id}.png. They need no key, because an <img> tag cannot send one, and they never change for a given game version, so cache them as long as you like.