bx_live_… bearer tokens Bluprynt operators issue per integrator. There is no self-serve key page; keys are issued, shown once, and stored only as a SHA-256 hash.
Key concepts
Get a key
Ask product@bluprynt.com for an exchange key, naming the scopes you need. The plaintext is shown once at issue — store it immediately. Bluprynt keeps only its hash and can’t recover it; a lost key is revoked and reissued.Send the key
Bearer bx_live_<43 chars>. Malformed shapes — a missing scheme, a lowercase scheme, or extra text — are rejected as api_key_invalid and never fall through to another auth method.
Route ↔ scope
watchlist:write doesn’t imply monitoring:read — a key that edits the watchlist but can’t read it is valid. Ask for the combination your integration needs.
What rejects your key
Rejected body (illustrative)
Keep the key safe
- Store it in a secret manager. The plaintext is unrecoverable after issue.
- A leaked key can read your watchlist and, with
watchlist:write, mutate it. Ask Bluprynt to revoke it —revokedAttakes effect immediately and the key authenticates nothing afterwards. - Use separate keys per environment so revocation stays scoped.
FAQ
Why 403 instead of 404 on routes my key can't call?
Why 403 instead of 404 on routes my key can't call?
Deliberate: the API answers
api_key_not_permitted so you can tell “wrong scope or key” apart from “this route will never accept keys”. The route exists — it just isn’t for you.Can I get more scopes later?
Can I get more scopes later?
Yes — ask Bluprynt. Scopes are set per key at issue and can be adjusted or reissued.
Does a key expire?
Does a key expire?
Keys have no automatic expiry. They authenticate until revoked (
revokedAt), which is immediate.Related
- Rate limits — the per-key budget
- Errors — the full
codetable