Skip to main content

Authentication

All Agent API endpoints require authentication via API key.

Getting an API Key​

  1. Visit bankr.bot/api-keys
  2. Sign in to your Bankr account
  3. Generate a new API key
  4. Check the features it needs — new keys have Wallet API and Agent API access (and read-write mode) on by default; turn off what the key doesn't use
Important

Each endpoint checks its own flag on the key: /agent/prompt needs Agent API access, and wallet writes such as /wallet/transfer need Wallet API access. A key without the required access gets a 403.

Using Your API Key​

Include your API key in the X-API-Key header with every request (Authorization: Bearer <key> also works). Load it from an environment variable such as BANKR_API_KEY rather than hard-coding it:

curl -X POST https://api.bankr.bot/agent/prompt \
-H "Content-Type: application/json" \
-H "X-API-Key: $BANKR_API_KEY" \
-d '{"prompt": "what is the price of ETH?"}'

Error Responses​

Missing or Invalid API Key (401)​

{
"error": "API key required",
"message": "Please provide a valid API key in the x-api-key header or Authorization: Bearer header"
}

A revoked or unknown key answers {"error": "Invalid API key", "message": "The provided API key is invalid or inactive"}.

Agent Access Not Enabled (403)​

{
"error": "Agent API access not enabled",
"message": "This API key does not have Agent API access enabled. Enable it in your API settings at https://bankr.bot/api-keys"
}

Access Control and Key Security​

Keys can also be read-only, locked to an IP allowlist, or limited to allowlisted recipients. See API Keys for each control and its error response, and for what to do if a key leaks.