Authentication
Every request must include an API key as a Bearer token:
Authorization: Bearer ep_test_PUBLIC_ID_SECRETTenant administrators manage keys in Integrations. The complete value is shown only once when a key is created; the administration later displays only a safe prefix and its last-used timestamp.
Key types
Section titled “Key types”| Prefix | Environment | Host |
|---|---|---|
ep_test_ |
Sandbox | sandbox-api.easypick.cz |
ep_live_ |
Production | api.easypick.cz |
Using a key in the wrong environment returns 401 invalid_api_key.
Recommendations
Section titled “Recommendations”- Store the key in a secret manager or protected server-side environment variable.
- Never put it in browser JavaScript, a mobile application, a URL, or a Git repository.
- Create a separate key for each integration. A compromised key can then be revoked in isolation.
- Keep production and test configuration separate.
- To rotate a key, create and deploy the new key before revoking the old one.
Traffic limits
Section titled “Traffic limits”The default production limit is 120 requests per minute with a short burst of 30. Sandbox allows 60 requests per minute with a burst of 15. When exceeded, the API returns 429 and a Retry-After header in seconds.