Authentication

Authenticate every request with your Sovrn-issued API key.

Every request must include the API key Sovrn issued to you, in the x-api-key
request header:

x-api-key: <your-sovrn-api-key>

Send it on every call to the base URL in
Introduction. A request with a missing, invalid or
malformed key returns 401 with a plain-text body; see
Errors.

📘

One header is all you send

Sovrn's API gateway exchanges your x-api-key for an internal credential
before the request reaches the service, so you only ever send x-api-key.

Your key is scoped to the Curation API. A write key can create and edit deals
on your account. A read-only key can only read them: every write it sends
returns 403 with the message Insufficient scope. Treat either kind as a
secret.

Contact your Sovrn representative to obtain or rotate a key.


Did this page help you?