Skip to content
Cascade

DocPage

A screen in the Guides area.

CascadeDocs

Guides

Authentication

Every request is authenticated with an API key. Here is how to create one, use it, and rotate it safely.

Overview

Cascade uses bearer tokens. You create a key in the dashboard, send it in the Authorization header, and treat it like a password: it grants full access to your account.

API keys

Keys come in two kinds. A live key touches real data; a test key touches a sandbox. Both are shown once, at creation, and never again.

Never ship a key to the browser

Anything in client-side code is public. Keep keys on your server, and if one leaks, rotate it immediately.

Making a request

Send the key as a bearer token:

request.ts
const res = await fetch("https://api.example.com/v1/entries", {  headers: {    Authorization: `Bearer ${process.env.API_KEY}`,  },});const data = await res.json();
Language: ts

Rotating a key

Create the new key, deploy it, then revoke the old one. Doing it in that order means zero downtime.