Developer
API Authentication
Authenticate requests to the Cafora Host API.
All API requests to Cafora Host require authentication via API key.
API Key Header
Include your API key in the Authorization header of every request:
Authorization: Bearer YOUR_API_KEYCreating API Keys
See API Keys for instructions on creating and managing API credentials.
Security Best Practices
- Never expose API keys in client-side code or public repositories
- Store API keys in environment variables or secure secret management
- Use separate keys for development and production
- Rotate keys periodically
- Revoke keys that are no longer in use
# Example: Store API key as environment variable
export CAFORA_API_KEY=your-api-key-hereAPI keys grant full access to your servers. Treat them like passwords. If a key is compromised, revoke it immediately and generate a new one.