Authentication
Every API request must include a valid partner API key.
Headers
Send your key using either header (same permissions):
Authorization: Bearer pr_live_YOUR_API_KEY # or X-API-Key: pr_live_YOUR_API_KEY
Key format
Keys look like pr_live_… or pr_test_…. Live keys require an active subscription. Test keys are read-only for the same plan (no match ingest).
Plans
The billed plan is enforced on every live request — not only at key creation. A Starter key that somehow lists write:matches still receives 403 plan_forbidden. Successful 2xx responses count toward the monthly cap; over the cap is 429 rate_limit_exceeded.
- Starter — 10,000 requests/month. Scopes:
read:players,read:rankings. Lookup, search, cards, progress, H2H, public rankings. No match ingest, predict/pair, coach analysis, or private player/roster writes. - Pro — 100,000 requests/month. Starter scopes plus
read:intelligence,write:players,write:matches. - Enterprise — custom fair-use quota (default 2,000,000 unless your contract sets another number) plus
write:external-ratings.
Scopes
Each key carries scopes, clipped to the plan. Missing scope → 403 forbidden. Feature not on the plan → 403 plan_forbidden.
read:players— GET player, search, matches, progress, card, H2H, roster reads (Starter+)read:rankings— GET rankings (Starter+)read:intelligence— POST predict / compare / pair, GET player/roster analysis (Pro+)write:players— POST players, create/update rosters (Pro+)write:matches— POST matches; GET match list/session recap also acceptsread:players(Pro+ to ingest)write:external-ratings— store third-party labels your product already shows (Enterprise)
Security practices
- Never expose keys in mobile apps or front-end JavaScript
- Rotate keys from the dashboard if leaked
- Use separate keys per environment (staging vs production)
- Pass
X-Request-Idfor support correlation (optional; we echo it back)