Skip to content

Authentication

Every request must include an API key as a Bearer token:

Authorization: Bearer ep_test_PUBLIC_ID_SECRET

Tenant administrators manage keys in Integrations. The complete value is shown only once when a key is created; the administration later displays only a safe prefix and its last-used timestamp.

Prefix Environment Host
ep_test_ Sandbox sandbox-api.easypick.cz
ep_live_ Production api.easypick.cz

Using a key in the wrong environment returns 401 invalid_api_key.

  • Store the key in a secret manager or protected server-side environment variable.
  • Never put it in browser JavaScript, a mobile application, a URL, or a Git repository.
  • Create a separate key for each integration. A compromised key can then be revoked in isolation.
  • Keep production and test configuration separate.
  • To rotate a key, create and deploy the new key before revoking the old one.

The default production limit is 120 requests per minute with a short burst of 30. Sandbox allows 60 requests per minute with a burst of 15. When exceeded, the API returns 429 and a Retry-After header in seconds.