Skip to content

Authentication

Integrator appendix. Cleared REST authenticates with short-lived or rotatable API keys prefixed {API_KEY_PREFIX_EXAMPLE}. Send them as Bearer tokens.

Maturity: By arrangement for Early Access partners. Keys are not self-serve until Integration Surfaces say Live.

Model

PartyResponsibility
BlockSkunk / Early Access opsMint and revoke keys; bind scopes and environment
IntegratorStore secrets server-side; rotate on revoke; never embed in browsers or mobile apps
Cleared APIValidates key, enforces scopes, returns public error categories

Cleared does not use end-user OAuth for the venue gate path in MVP. Dashboard/desk login (if any) is separate from API keys.

Bearer header

GET /v1/eligibility/{subject_ref} HTTP/1.1
Host: api.cleared.example
Authorization: Bearer FAKESECRET_y3z4a5b6c7d8e9f0g1h2
Accept: application/json

Synthetic success does not imply Live maturity. Base URL for your environment is issued with the key (default docs placeholder: {API_ORIGIN}).

Key lifecycle

  1. Request access — contracted Early Access or demo arrangement.
  2. Mint — receive clr_… secret once; copy to your secret store.
  3. Use — server-side only; one key per environment recommended.
  4. Rotate / revoke — on compromise or personnel change; old key fails with unauthorized category.

Do not log full keys. Prefer last-four display in your own ops tools.

Environment

Variable (illustrative)Purpose
CLEARED_API_BASEEnvironment base URL
CLEARED_API_KEYclr_ secret

Idempotency for seal/onboard uses Idempotency-Key (see API reference) — not a substitute for auth.

Was this page clear?