Website →

Authentication

Learn how to authenticate API requests with your ShildMatrix API key.

API key header

All validation endpoints require a valid API key sent in the X-API-Key header.

X-API-Key: YOUR_API_KEY

You can generate API keys from the dashboard under Settings → API Keys. Each account supports up to 5 keys.

Base URL

The API is available at:

http://localhost:8000/api/v1/

In production, replace with your deployed API base URL.

Example request

Example request

curl --request GET \
  --url 'http://localhost:8000/api/v1/status/' \
  --header 'accept: application/json' \
  --header 'X-API-Key: YOUR_API_KEY'

Example response

{
  "success": true,
  "status": "ok",
  "datasets": {
    "disposable_domains": {
      "count": 167611,
      "version": "2026-09-03"
    },
    "free_providers": {
      "version": "2026-07-01"
    },
    "role_prefixes": {
      "version": "2026-07-01"
    }
  }
}

Dashboard authentication

Dashboard endpoints (/dashboard/*, /lists/*, /billing/subscription/) use JWT Bearer tokens obtained via /auth/jwt/create/. These power the web dashboard, not the public validation API.

POST /check/ also accepts JWT when the body includes api_key_id (used by the API Playground). GET /status/ and GET /usage/ require X-API-Key only.

Error responses

If authentication fails, the API returns:

{
  "error": "Invalid or missing API key"
}

Never expose your API key in client-side code. Make validation requests from your backend server.