Authentication
API keys, IP allowlists and rate limits.
The key
Every request carries your API key as a bearer token. Requests and responses are JSON over HTTPS. The same key works for both product families, gift cards & software and eSIMs.
Authorization: Bearer nc_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Managing keys
- Keys are created in Account → API. Creating one needs a one-time code sent to your own phone or email.
- A key is shown once. We only keep a fingerprint of it, so we cannot show it again: create a new one if it is lost.
- You can hold up to 5 live keys, for example one per server or environment, and revoke any of them at any time. A revoked key stops working at once.
IP allowlist
Optionally restrict a key to the IP addresses of your servers (up to 10, IPv4 or IPv6). A request from any other address gets 403 ip_not_allowed. With an empty list the key works from anywhere.
Use the allowlist in production. A leaked key is then useless outside your servers.
Rate limits
| Limit | Per | When exceeded |
|---|---|---|
| 60 requests a minute | API key | HTTP 429: wait and retry |
| 20 orders a minute | API key | HTTP 429: wait and retry |
The order limit counts every call that spends or refunds money, together: POST /orders, POST /esim/orders, eSIM top-ups and eSIM cancels.
Keeping the key safe
- Call the API from your server only. Never put the key in a mobile app, a web page or a public repository.
- If a key may have leaked, revoke it in the dashboard first, then create a new one.
- The key can spend your balance. It cannot add balance, change your account or read your website orders.