Skip to main content

API Key Authentication

Trestle controls access to the API and data via an API Key. The API key is the primary authentication method for your account. Your usage is recorded and reported via the API Key. You may use a single API key for multiple Trestle APIs.

Getting an API Key

To get an API key:
  1. Sign up for a Developer Portal account
  2. Once approved, you can send a request to any of Trestle’s APIs
  3. Your API key will be available in the Developer Portal

Using Your API Key

All API requests require authentication via the x-api-key header.

Header Format

Include your API key in the request header:

Example Request

HTTP Methods

We recommend using GET for simplicity. Include the API key in the header:

POST

POST is also supported. In this case, api_key must be in the request body and not part of the URL:

Security Best Practices

Keep your API key secure and never expose it in client-side code or public repositories.
  • Store API keys in environment variables
  • Use different API keys for different environments (development, staging, production)
  • Rotate API keys regularly
  • Never commit API keys to version control

Error Responses

400 Bad Request

  • Indicates that the server cannot process the request due to client-side errors.

403

  • Invalid API Key: Indicates that the API key is either incorrect or has been deactivated.
  • API Key Missing: Indicates that your request did not include an API key.
  • API Key Expired: Indicates that the API key has expired.

429 Too Many Requests

  • API Key has exceeded its rate limit.

500 Internal Server Error

  • An unexpected error occurred on the server.

Need Help?

If you’re having trouble with authentication, check our FAQ or contact support@trestleiq.com.