Authentication

The Frame API uses API keys to authenticate requests. You can view and manage your API keys in the Frame Dashboard.

Test mode secret keys have the prefix sk_sandbox_ and live mode secret keys have the prefix sk_production_. Alternatively, you can use restricted API keys for granular permissions.

Your API keys carry many privileges, so be sure to keep them secure! Do not share your secret API keys in publicly accessible areas such as GitHub, client-side code, and so forth.

Authentication is performed via HTTP Bearer Authentication. Provide your API key as the bearer token value. All API requests must be made over HTTPS. Calls made over plain HTTP will fail. API requests without authentication will also fail.

Authorization: Bearer <your_api_key>
AUTHENTICATED REQUEST
curl --request GET \
  --header 'Authorization: Bearer <your_api_key>'