Documentation
Browse documentation

Authentication

Authenticate API requests with a FiscalRail secret key.
View as Markdown

FiscalRail authenticates API requests with secret keys. Create the first key from Developers → API keys in the dashboard. Once authenticated, you can manage API keys through the API.

Send your key as a Bearer token in the Authorization header:

Authorization: Bearer fra_live_...

Secret keys provide access to an account and must only be used in trusted server-side code. Do not put them in browser code, mobile applications, source control or public documentation.

Test keys begin with fra_test_; live keys begin with fra_live_. Existing ak_test_ and ak_ keys remain valid. A secret key is only shown once when it is created, so store it securely.

New keys contain a 44-character Base58 random payload followed by a six-character Base58 checksum. The checksum is CRC32 of the prefix and payload; it helps secret scanners recognize leaked keys without checking them against FiscalRail. It does not prove a key is active.

Read the key from your application's secret manager and pass it explicitly to your SDK client:

import os

from fiscalrail import FiscalRail

client = FiscalRail(os.environ["FISCALRAIL_API_KEY"])

Neither SDK reads the key from environment variables automatically. See the Python SDK guide or Ruby SDK guide for installation and connection management.