API
Authentication
Bearer tokens over HTTPS. No token carries a signing scope, because there is no signing path to scope.
curl https://api.accuren.xyz/v1/positions \
-H "Authorization: Bearer $ACCUREN_API_KEY"Keys begin acc_live_. Anything that does not is rejected before it is looked up, so a truncated paste fails as 401 unauthorized rather than as a slow lookup miss.
#What a key can do
One key, one account, everything under /v1. Accuren issues no scopes, so a key that can read positions can also add a wallet or generate an export. Plan for that: the boundary is the key, not a permission inside it.
There is no write path for funds to scope
Not restricted, not gated — absent. Accuren holds no keys and submits no transactions, so there is no endpoint a key could reach that moves anything. That is why the missing scope system costs you nothing that matters: the worst a leaked key does is read your record and watch an address.
#Keys
- Create and revoke keys per integration, never share one between them.
- A key is shown once. Store it in your secret manager, not in the repo.
- Rotate by creating the new key, deploying, then revoking the old one — both work during the overlap.
Agents get their own key
Not because it can be narrowed — it cannot — but because it can be revoked on its own. A confused agent and your own scripts should never be sharing the credential you have to pull.