Skip to content

Authentication

Every API request must include a valid partner API key.

Headers

Send your key using either header (same permissions):

cURL
Authorization: Bearer pr_live_YOUR_API_KEY
# or
X-API-Key: pr_live_YOUR_API_KEY

Key format

Keys look like pr_live_… or pr_test_…. Live keys require an active subscription. Test keys are read-only for the same plan (no match ingest).

Plans

The billed plan is enforced on every live request — not only at key creation. A Starter key that somehow lists write:matches still receives 403 plan_forbidden. Successful 2xx responses count toward the monthly cap; over the cap is 429 rate_limit_exceeded.

  • Starter — 10,000 requests/month. Scopes: read:players, read:rankings. Lookup, search, cards, progress, H2H, public rankings. No match ingest, predict/pair, coach analysis, or private player/roster writes.
  • Pro — 100,000 requests/month. Starter scopes plus read:intelligence, write:players, write:matches.
  • Enterprise — custom fair-use quota (default 2,000,000 unless your contract sets another number) plus write:external-ratings.

Scopes

Each key carries scopes, clipped to the plan. Missing scope → 403 forbidden. Feature not on the plan → 403 plan_forbidden.

  • read:players — GET player, search, matches, progress, card, H2H, roster reads (Starter+)
  • read:rankings — GET rankings (Starter+)
  • read:intelligence — POST predict / compare / pair, GET player/roster analysis (Pro+)
  • write:players — POST players, create/update rosters (Pro+)
  • write:matches — POST matches; GET match list/session recap also accepts read:players (Pro+ to ingest)
  • write:external-ratings — store third-party labels your product already shows (Enterprise)

Security practices

  • Never expose keys in mobile apps or front-end JavaScript
  • Rotate keys from the dashboard if leaked
  • Use separate keys per environment (staging vs production)
  • Pass X-Request-Id for support correlation (optional; we echo it back)