Authentication
Integrator appendix. Cleared REST authenticates with short-lived or rotatable API keys prefixed {API_KEY_PREFIX_EXAMPLE}. Send them as Bearer tokens.
Maturity: By arrangement for Early Access partners. Keys are not self-serve until Integration Surfaces say Live.
Model
| Party | Responsibility |
|---|---|
| BlockSkunk / Early Access ops | Mint and revoke keys; bind scopes and environment |
| Integrator | Store secrets server-side; rotate on revoke; never embed in browsers or mobile apps |
| Cleared API | Validates key, enforces scopes, returns public error categories |
Cleared does not use end-user OAuth for the venue gate path in MVP. Dashboard/desk login (if any) is separate from API keys.
Bearer header
GET /v1/eligibility/{subject_ref} HTTP/1.1
Host: api.cleared.example
Authorization: Bearer FAKESECRET_y3z4a5b6c7d8e9f0g1h2
Accept: application/json
Synthetic success does not imply Live maturity. Base URL for your environment is issued with the key (default docs placeholder: {API_ORIGIN}).
Key lifecycle
- Request access — contracted Early Access or demo arrangement.
- Mint — receive
clr_…secret once; copy to your secret store. - Use — server-side only; one key per environment recommended.
- Rotate / revoke — on compromise or personnel change; old key fails with
unauthorizedcategory.
Do not log full keys. Prefer last-four display in your own ops tools.
Environment
| Variable (illustrative) | Purpose |
|---|---|
CLEARED_API_BASE | Environment base URL |
CLEARED_API_KEY | clr_ secret |
Idempotency for seal/onboard uses Idempotency-Key (see API reference) — not a substitute for auth.