Skip to content
LogoLogo

Authentication

Every /v2* request needs an API key, except GET /health and GET /openapi.json. Send the key in the api-key header.

GET /transfers
api-key: sk_test_a1b2c3...

The header is evaluated as the credential, not a cookie. Even if the browser sent a session cookie, an API key must be present.

Key format

Keys self-identify their environment by prefix:

PrefixEnvironment
sk_test_Testnet
sk_live_Mainnet

A key is 64 random characters after the prefix, for example sk_live_0f9a....

Environment binding

A test key works on testnet chains. A live key works on mainnet chains. The API enforces this on POST /transfers; using the wrong key for a chain returns 403 with the chain-not-allowed-for-key-environment problem.

{
  "type": "https://docs.mure.app/problems/chain-not-allowed-for-key-environment",
  "title": "Chain not allowed for key environment",
  "status": 403,
  "detail": "The chain is not allowed for the API key's environment.",
  "instance": "https://api.mure.app/v2/transfers",
  "correlationId": "01J0000000000000000000000A",
  "details": { "chainId": 1, "keyEnv": "test" }
}

Use sk_test_ keys for development against testnets. Use sk_live_ keys for production traffic.

Authentication errors

The auth gate runs before routing and returns RFC 9457 problem details, like every other /v2 failure. The 401, 403, and 429 responses appear in /v2/openapi.json, so generated clients describe them.

StatusTypeWhen
401https://docs.mure.app/problems/missing-api-keyNo api-key header.
403https://docs.mure.app/problems/invalid-api-keyKey is invalid, expired, disabled, or belongs to a deleted user.
403https://docs.mure.app/problems/chain-not-allowed-for-key-environmentThe key's environment cannot act on a chain referenced by the request.

Rate limits

The default limit is 50 requests per minute per key. When you exceed it, the API returns 429 with the rate-limited problem. Wait the value of the Retry-After header, then retry.

{
  "type": "https://docs.mure.app/problems/rate-limited",
  "title": "Rate limited",
  "status": 429,
  "detail": "Too many requests.",
  "instance": "https://api.mure.app/v2/transfers",
  "correlationId": "01J0000000000000000000000A"
}

Getting a key

Sign in to your Mure account in a browser, then create a key from that session:

POST /auth/api-key/create

The request body carries the key name.

{
  "name": "production"
}

The response contains the full key once. Copy it now; it is not shown again. The key is stored as a hash, so Mure cannot recover it if you lose it. Delete and recreate a key to rotate it.