Authentication

API keys: format, creation, rotation and error handling.

Every API request authenticates with the X-API-Key header:

curl "https://api.kavik.email/api/v1/verify?email=jane@acmecorp.com" \
  -H "X-API-Key: eva_your_key"

Key properties

  • 32-byte random values with the eva_ prefix.
  • Shown once at creation. Store it somewhere safe; we keep only a bcrypt hash and cannot show it again.
  • Create, name and revoke keys in the dashboard under API keys. Revocation takes effect immediately.
  • All keys share the account’s plan quota and rate limits.

Errors

Status Meaning
401 Missing, invalid, or revoked key. Response body: {"error": "...", "code": "UNAUTHORIZED"}
429 Rate limit or quota exceeded, with X-RateLimit-* headers to pace by. Top up with a credit pack or upgrade for quota.
429 Rate limit exceeded. Back off using the X-RateLimit-Reset header.

Never put a key in client-side code, in a URL, or in a repository. If one leaks, revoke it in the dashboard and create a new one.