Authentication
Authenticate with a personal API key sent as a Bearer token.
Every request to the Trollflix API is authenticated with your API key. The key belongs to your account: whatever you do with it, you do as yourself.
Get a key
Create it in Settings → Integrations, on the website or in the Trollflix app (Profile → Settings → Integrations).
- You can have one key at a time.
- The full key is shown once, right after you create or rotate it. Trollflix stores only a hash of it, so nobody (us included) can show it to you again.
- Settings shows a masked hint such as
tfx_3f9a...c2b1, when the key was last used and how many requests it has made, so you can tell which key is live.
Keys look like this: tfx_ followed by 48 lowercase hexadecimal characters.
Send the key
Put the key in the Authorization header with the Bearer scheme:
Authorization: Bearer tfx_3f9a1c...The header is the only place the key is accepted. Query strings end up in
logs and browser history, so ?api_key= is deliberately not supported.
If the header is missing or the key is wrong, the API answers with HTTP 401:
| HTTP | error_message_code | Meaning |
|---|---|---|
| 401 | api_key_missing | No Authorization: Bearer ... header was sent. |
| 401 | api_key_invalid | The key is malformed, was rotated, or was deleted. |
{ "success": false, "error_message_code": "api_key_invalid" }Rotate a key
Rotate creates a new key and revokes the old one in the same moment.
Use it on a schedule, when someone with access leaves, or as soon as you suspect
a leak. Anything still using the old key starts getting api_key_invalid
immediately, so update your environment right after rotating.
Delete a key
Delete revokes the key without replacing it. You can create a new one at any time.
Each of these actions is also documented as an endpoint in API keys.