TrollflixDevelopers

Authentication

Authenticate with a personal API key sent as a Bearer token.

Every request to the Trollflix API is authenticated with your API key. The key belongs to your account: whatever you do with it, you do as yourself.

Get a key

Create it in Settings → Integrations, on the website or in the Trollflix app (Profile → Settings → Integrations).

  • You can have one key at a time.
  • The full key is shown once, right after you create or rotate it. Trollflix stores only a hash of it, so nobody (us included) can show it to you again.
  • Settings shows a masked hint such as tfx_3f9a...c2b1, when the key was last used and how many requests it has made, so you can tell which key is live.

Keys look like this: tfx_ followed by 48 lowercase hexadecimal characters.

Send the key

Put the key in the Authorization header with the Bearer scheme:

Authorization: Bearer tfx_3f9a1c...

The header is the only place the key is accepted. Query strings end up in logs and browser history, so ?api_key= is deliberately not supported.

If the header is missing or the key is wrong, the API answers with HTTP 401:

HTTPerror_message_codeMeaning
401api_key_missingNo Authorization: Bearer ... header was sent.
401api_key_invalidThe key is malformed, was rotated, or was deleted.
{ "success": false, "error_message_code": "api_key_invalid" }

Rotate a key

Rotate creates a new key and revokes the old one in the same moment. Use it on a schedule, when someone with access leaves, or as soon as you suspect a leak. Anything still using the old key starts getting api_key_invalid immediately, so update your environment right after rotating.

Delete a key

Delete revokes the key without replacing it. You can create a new one at any time.

Each of these actions is also documented as an endpoint in API keys.

Keep it safe