NovaCodes

Authentication

API keys, IP allowlists and rate limits.

Every request carries your API key as a bearer token. Requests and responses are JSON over HTTPS. The same key works for both product families, gift cards & software and eSIMs.

Authorization: Bearer nc_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Managing keys

  • Keys are created in Account → API. Creating one needs a one-time code sent to your own phone or email.
  • A key is shown once. We only keep a fingerprint of it, so we cannot show it again: create a new one if it is lost.
  • You can hold up to 5 live keys, for example one per server or environment, and revoke any of them at any time. A revoked key stops working at once.

IP allowlist

Optionally restrict a key to the IP addresses of your servers (up to 10, IPv4 or IPv6). A request from any other address gets 403 ip_not_allowed. With an empty list the key works from anywhere.

Use the allowlist in production. A leaked key is then useless outside your servers.

Rate limits

LimitPerWhen exceeded
60 requests a minuteAPI keyHTTP 429: wait and retry
20 orders a minuteAPI keyHTTP 429: wait and retry

The order limit counts every call that spends or refunds money, together: POST /orders, POST /esim/orders, eSIM top-ups and eSIM cancels.

Keeping the key safe

  • Call the API from your server only. Never put the key in a mobile app, a web page or a public repository.
  • If a key may have leaked, revoke it in the dashboard first, then create a new one.
  • The key can spend your balance. It cannot add balance, change your account or read your website orders.