Authentication
API keys
How to authenticate requests with x-auth-key.
Protected endpoints require an API key issued to you by the Upward team. Send it in the x-auth-key header on every request.
x-auth-key: upw_live_ab12…7f30Handling keys safely
- Call the API from your backend only — never ship a key to a browser or mobile app.
- Keys can be disabled or rotated at any time from the Upward admin console.
- A key may carry an expiry date; expired or disabled keys return 401.
- Every request is logged against the key: endpoint, status, duration and IP.