Authentication
Authenticate with Combee using an x-api-key header.
since 0.1.0-beta
Combee authenticates every public request with an API key sent in the x-api-key header.
API keys
- Keys look like
cmb_sk_.... - Create and revoke them from the Platform → API Keys section.
- A key is scoped to one account; it can access only that account's Cells.
Using a key
Every SDK request sends the key automatically:
const combee = new Combee({
baseUrl: 'https://api.combee.cloud',
apiKey: process.env.COMBEE_API_KEY!,
});Security notes
- Never commit keys to source control; use environment variables or a secret manager.
- Combee stores only a hash of your key — the plaintext is shown once when created.
- If a key leaks, revoke it immediately; revocation takes effect on the next request.
- Accessing another account's Cell is rejected — cross-tenant requests behave as not found (404) rather than leaking existence.
REST
If you call the REST API directly, send the header on every request:
curl https://api.combee.cloud/v1/databases \
-H "x-api-key: $COMBEE_API_KEY"