Authentication

Every request to the IP Raccoon API is authenticated with an API key sent in the Authorization header, with no Bearer prefix. Requests without a valid key receive a 401 Unauthorized.

Authorization: <your-api-key>

Getting a key

API keys are manually managed via the dashboard. Go to the dashboard, and locate the Credentials section on the bottom left of the page, then click the key icon (Manage keys) to see all your active API keys and revoke them or create new ones.

Each key authenticates independently, but all of them draw from the same credit balance. For example, you can create a different one for each of your environments (production, staging, …), and if needed revoke any of them without affecting the others.

Key lifecycle

  • Keys don't expire on their own — they authenticate until you revoke them.
  • Revoking is immediate and permanent: once a key is gone, any request still using it gets 401 right away.
  • An account needs to have at least one active key — the last remaining one can't be revoked. If you need to revoke it, you will need to create a new one beforehand.
  • Store keys server-side; never embed them in client bundles.

Rotating keys regularly limits the blast radius of a leak.