How to get a Public API key and send it on every request.
The Public API uses a single API key sent in the Authorization header. Keys are issued by Bluprynt per integrator — there is no self-serve key page, so Passport can’t create or rotate one for you.
Ask product@bluprynt.com for a Public API key. Keys identify your integration and are issued per environment or partner on request.
The Integrations page in Passport lists third-party data providers (1) — TRM Labs, Forta and similar. It does not issue or manage API keys — key requests go through Bluprynt directly.
Passport's Integrations page holds data providers (1), not API keys.
In the Available authorizations dialog, the api-key scheme is an Authorization header (1). Paste your key into Value (2) — the key alone, no Bearer — and click Authorize (3), then Close. Nothing is sent until you call a route.
The Authorize dialog sends your key as the raw Authorization header on every Try it out call.
3
Run a route
Open any route, click Try it out, fill in the parameters and click Execute. The response body, status and headers appear inline.
No. GET /api/v1/badges/{credential_type} is public by design — it renders on pages you don’t control, like a token listing. See Badges.
Can one key call both Bluprynt APIs?
No. The Public API and the Explorer API issue different keys with different formats. A Public API key is a raw secret; an Explorer API key is a bx_live_… bearer token with scopes.
Is there IP allowlisting or OAuth?
No. The only credential check is the key value itself, compared against the keys Bluprynt has issued. Treat the key like a password.