Authentication
API keys
Every call to the API needs a key. Keys are free, allow 5,000 requests per day, and let us tell you if something you depend on is about to change.
Getting a key
Register for an account, sign in, and open API keys in your dashboard. Creating a key shows it once. We store only a hash of it, so it cannot be shown again. If you lose it, revoke it and create another.
Every key begins narc_live_.
Sending a key
Either header works. Pick one.
The key on its own: X-API-Key: narc_live_…
Scheme and key: Authorization: Api-Key narc_live_…
Limits
| Access | Limit | Who |
|---|---|---|
| Key | 5,000 requests per day | Any registered account. Counted per key. |
| Partner | Unmetered | Set by NARC for government and research systems. |
Over the limit you get 429 Too Many Requests. Wait for the
window to pass rather than retrying immediately; retries still
count.
Keeping a key safe
A key identifies your account, so treat it like a password: keep it on your server, in an environment variable, out of version control.
Don’t put a key in a web page
Anything in browser JavaScript is readable by anyone who opens the page. Call the API from your backend and pass the result on to your pages.
Revoking
Revoke a key from your dashboard and it stops working on the next request. Revoking is immediate and cannot be undone; create a new key and update your application.