Authentication
Every endpoint except the item icons needs a key, sent in the Authorization header:
GET /v1/recipes/milk-stout HTTP/1.1
Authorization: Bearer td_live_<32 letters and digits>_<6-character checksum>
The last six characters are a checksum, so a mistyped key is refused at once with 401.
Never in the URL
A request with the key in the query string (?key=, ?token=, ?api_key=…) is refused with
400 token-in-url, even when the key is valid. URLs end up in server logs, browser history and Referer headers.
Keep the key on a server
- Read it from an environment variable or a secret manager, never from your source code.
- Do not ship it in a website, a mobile app or a desktop app: anyone can extract it from there. Call the API from your own backend and cache the answers.
- Do not commit it. If it reaches a public repository, revoke it at once.
Revoking
Revoke a key in the dashboard. It stops working within a minute everywhere. You can have up to three active keys, which lets you rotate one without downtime: create the new key, deploy it, then revoke the old one.
Icons
Item sprites are plain images at /v1/icons/{item_id}.png. They need no key, because an <img> tag cannot send
one, and they never change for a given game version, so cache them as long as you like.