Authentication
Every /v2* request needs an API key, except GET /health and GET /openapi.json. Send the key in the api-key header.
GET /transfers
api-key: sk_test_a1b2c3...
The header is evaluated as the credential, not a cookie. Even if the browser sent a session cookie, an API key must be present.
Key format
Keys self-identify their environment by prefix:
| Prefix | Environment |
|---|---|
sk_test_ | Testnet |
sk_live_ | Mainnet |
A key is 64 random characters after the prefix, for example sk_live_0f9a....
Environment binding
A test key works on testnet chains. A live key works on mainnet chains. The API enforces this on POST /transfers; using the wrong key for a chain returns 403 with the chain-not-allowed-for-key-environment problem.
{
"type": "https://docs.mure.app/problems/chain-not-allowed-for-key-environment",
"title": "Chain not allowed for key environment",
"status": 403,
"detail": "The chain is not allowed for the API key's environment.",
"instance": "https://api.mure.app/v2/transfers",
"correlationId": "01J0000000000000000000000A",
"details": { "chainId": 1, "keyEnv": "test" }
}Use sk_test_ keys for development against testnets. Use sk_live_ keys for production traffic.
Authentication errors
The auth gate runs before routing and returns RFC 9457 problem details, like every other /v2 failure. The 401, 403, and 429 responses appear in /v2/openapi.json, so generated clients describe them.
| Status | Type | When |
|---|---|---|
| 401 | https://docs.mure.app/problems/missing-api-key | No api-key header. |
| 403 | https://docs.mure.app/problems/invalid-api-key | Key is invalid, expired, disabled, or belongs to a deleted user. |
| 403 | https://docs.mure.app/problems/chain-not-allowed-for-key-environment | The key's environment cannot act on a chain referenced by the request. |
Rate limits
The default limit is 50 requests per minute per key. When you exceed it, the API returns 429 with the rate-limited problem. Wait the value of the Retry-After header, then retry.
{
"type": "https://docs.mure.app/problems/rate-limited",
"title": "Rate limited",
"status": 429,
"detail": "Too many requests.",
"instance": "https://api.mure.app/v2/transfers",
"correlationId": "01J0000000000000000000000A"
}Getting a key
Sign in to your Mure account in a browser, then create a key from that session:
POST /auth/api-key/create
The request body carries the key name.
{
"name": "production"
}The response contains the full key once. Copy it now; it is not shown again. The key is stored as a hash, so Mure cannot recover it if you lose it. Delete and recreate a key to rotate it.