Authentication
Every request to the IP Raccoon API is authenticated with an API key
sent in the Authorization header, with no Bearer prefix. Requests
without a valid key receive a 401 Unauthorized.
Authorization: <your-api-key>
Getting a key
API keys are manually managed via the dashboard. Go to the dashboard, and locate the Credentials section on the bottom left of the page, then click the key icon (Manage keys) to see all your active API keys and revoke them or create new ones.
Each key authenticates independently, but all of them draw from the same
credit balance. For example, you can create a different one for each of
your environments (production, staging, …), and if needed revoke any
of them without affecting the others.
Key lifecycle
- Keys don't expire on their own — they authenticate until you revoke them.
- Revoking is immediate and permanent: once a key is gone, any request
still using it gets
401right away. - An account needs to have at least one active key — the last remaining one can't be revoked. If you need to revoke it, you will need to create a new one beforehand.
- Store keys server-side; never embed them in client bundles.
Rotating keys regularly limits the blast radius of a leak.