Skip to main content
Every request to a CS2Cap market-data endpoint must include an API key in the Authorization header. There are no cookies, sessions, or OAuth flows for API access — your key is the only credential the API requires. Keep it secret and never commit it to source control.

Get your API key

1

Create an account

Sign up at cs2cap.com using OAuth. No password is required.
2

Verify your email address

Add and verify an email address on your account. Email verification is required before any API key can be issued or reissued.
3

Generate your key

Go to cs2cap.com/account/api-keys and generate your initial API key. Copy it immediately — it is only shown once.
4

Add the key to your SDK configuration

Configure the SDK with your API key once. The client sends the required Authorization header on every request.
You can only have one active API key per account. Generating a new key revokes your current key and all child keys issued from it.

Send the Authorization header

Pass your API key as a Bearer token in the Authorization header on every request.

Code examples

Store your key in an environment variable (e.g., CS2C_API_KEY) rather than hard-coding it in your source files.

API key rules

  • One active key per account. You cannot have multiple active keys on a single account unless you use sub-keys (available on Quant).
  • Email verification is required. You must have a verified email address on your account before the API will issue or reissue a key.
  • Keys are sensitive. Treat your API key like a password. Do not share it publicly or include it in client-side code.

Reissuing your key

If your key is compromised or you want to rotate it, use the Account page or call POST /account/key/reissue. This root-key rotation endpoint is intentionally separate from the public SDK sub-key helpers. It:
  • Immediately revokes your current key
  • Revokes all child keys issued from your account
  • Returns a new key
Reissuing your key is irreversible. Any integrations using the old key will stop working immediately. Update all consumers before or immediately after reissuing.

Authentication error codes

When a request fails due to an authentication problem, the API returns a 401 or 403 response with a machine-readable code field. All error responses follow the same shape:
Last modified on July 12, 2026