Authorization header. There are no cookies, sessions, or OAuth flows for API access — your key is the only credential the API requires. Keep it secret and never commit it to source control.
Get your API key
1
Create an account
Sign up at cs2cap.com using OAuth. No password is required.
2
Verify your email address
Add and verify an email address on your account. Email verification is required before any API key can be issued or reissued.
3
Generate your key
Go to cs2cap.com/account/api-keys and generate your initial API key. Copy it immediately — it is only shown once.
4
Add the key to your SDK configuration
Configure the SDK with your API key once. The client sends the required
Authorization header on every request.Send the Authorization header
Pass your API key as a Bearer token in theAuthorization header on every request.
Code examples
API key rules
- One active key per account. You cannot have multiple active keys on a single account unless you use sub-keys (available on Quant).
- Email verification is required. You must have a verified email address on your account before the API will issue or reissue a key.
- Keys are sensitive. Treat your API key like a password. Do not share it publicly or include it in client-side code.
Reissuing your key
If your key is compromised or you want to rotate it, use the Account page or callPOST /account/key/reissue. This root-key rotation endpoint is intentionally separate from the public SDK sub-key helpers. It:
- Immediately revokes your current key
- Revokes all child keys issued from your account
- Returns a new key
Authentication error codes
When a request fails due to an authentication problem, the API returns a401 or 403 response with a machine-readable code field.
All error responses follow the same shape: