Skip to main content
The Explorer API authenticates integrators with scoped exchange keys — bx_live_… bearer tokens Bluprynt operators issue per integrator. There is no self-serve key page; keys are issued, shown once, and stored only as a SHA-256 hash.

Key concepts

Get a key

Ask product@bluprynt.com for an exchange key, naming the scopes you need. The plaintext is shown once at issue — store it immediately. Bluprynt keeps only its hash and can’t recover it; a lost key is revoked and reissued.

Send the key

The header must be exactly Bearer bx_live_<43 chars>. Malformed shapes — a missing scheme, a lowercase scheme, or extra text — are rejected as api_key_invalid and never fall through to another auth method.

Route ↔ scope

watchlist:write doesn’t imply monitoring:read — a key that edits the watchlist but can’t read it is valid. Ask for the combination your integration needs.

What rejects your key

Rejected body (illustrative)

Keep the key safe

  • Store it in a secret manager. The plaintext is unrecoverable after issue.
  • A leaked key can read your watchlist and, with watchlist:write, mutate it. Ask Bluprynt to revoke it — revokedAt takes effect immediately and the key authenticates nothing afterwards.
  • Use separate keys per environment so revocation stays scoped.

FAQ

Deliberate: the API answers api_key_not_permitted so you can tell “wrong scope or key” apart from “this route will never accept keys”. The route exists — it just isn’t for you.
Yes — ask Bluprynt. Scopes are set per key at issue and can be adjusted or reissued.
Keys have no automatic expiry. They authenticate until revoked (revokedAt), which is immediate.