Authentication

How the Poptin API authenticates requests: create an API key, send it as a bearer token, and interpret 401 and 403 responses.

The Poptin API authenticates every request with an API key you generate in the Poptin app. Requests without a valid key are rejected - there is no unauthenticated access, no anonymous read tier, and no session cookies. The API is served from https://api.popt.in/v1 and expects the key to be presented as a bearer token.

Get an API key

Create keys inside the Poptin app:

  1. Sign in and open My Account → API & Connections → API Keys.
  2. Generate a new key. It will start with pk_live_.
  3. Copy the key immediately. The full value is shown only once at creation. If you close the dialog without copying, revoke the key and create a new one.
  4. Store it server-side in an environment variable or a secrets manager. See API Security Standards for storage and handling rules.

Each key is scoped to the account or subaccount it was created in. Every call made with that key operates on - and can only see - that account's data. Keys cannot cross accounts. If your integration needs to work across several accounts, create a separate key in each and route requests accordingly.

Send the key

On every request, include your key in the standard Authorization header as Bearer pk_live_…. That single header authenticates the call; no other credential, cookie, or signature is required.

For live, executable examples, use the Try It explorer on any operation in the API Reference. Paste your key into the Authentication panel and it will be attached to the request automatically.

Common failures

Two status codes cover almost every auth problem:

  • 401 Unauthorized - The request has no Authorization header, the header is malformed, the token doesn't exist, or the account behind it is inactive or deleted. Fix: verify the header format and that the key is still active in My Account → API & Connections → API Keys.
  • 403 Forbidden - The key is valid, but the account is restricted from performing this operation (for example, plan restrictions or a suspended account). Fix: check account status in the Poptin app or contact support.

Retrying the same request with the same key will not resolve either error. Correct the credential or the account state first.

Next steps


Did this page help you?