Authentication
FiscalRail authenticates API requests with secret keys. Create the first key from Developers → API keys in the dashboard. Once authenticated, you can manage API keys through the API.
Send your key as a Bearer token in the Authorization header:
Authorization: Bearer fra_live_...
Secret keys provide access to an account and must only be used in trusted server-side code. Do not put them in browser code, mobile applications, source control or public documentation.
Test keys begin with fra_test_; live keys begin with fra_live_. Existing ak_test_ and ak_ keys remain valid. A secret key is only shown once when it is created, so store it securely.
New keys contain a 44-character Base58 random payload followed by a six-character Base58 checksum. The checksum is CRC32 of the prefix and payload; it helps secret scanners recognize leaked keys without checking them against FiscalRail. It does not prove a key is active.
Read the key from your application's secret manager and pass it explicitly to your SDK client:
import os
from fiscalrail import FiscalRail
client = FiscalRail(os.environ["FISCALRAIL_API_KEY"])
require "fiscalrail"
client = FiscalRail::Client.new(api_key: ENV.fetch("FISCALRAIL_API_KEY"))
Neither SDK reads the key from environment variables automatically. See the Python SDK guide or Ruby SDK guide for installation and connection management.