Authentication
All API v1 requests require an API key.
http
X-API-KEY: factulit_test_example_key
Accept: application/json
Content-Type: application/jsonKeys Belong to One Environment
The prefix of a key states which environment issued it, and a key is only valid against that environment's base URL:
| Prefix | Environment | Base URL |
|---|---|---|
factulit_test_ | Test | https://api.sandbox-factulit.es |
factulit_live_ | Production | https://api.factulit.es |
The pairing is checked before the key is looked up, so a mismatch always returns 401 and never reaches your data. There is no way to promote a test key to production: production issues its own key.
Key Handling
- Keep real keys on the server.
- Do not expose keys in browser JavaScript, mobile apps, public repositories, logs, or support screenshots.
- Rotate credentials when a key may have been exposed.
- Use placeholder values in documentation, tests, and examples.
Authentication Errors
| Status | Meaning |
|---|---|
401 | Missing, malformed, inactive, or invalid key, or a key that belongs to the other environment. |
403 | The key is valid but cannot be associated with an allowed business context. |