Developers

Developer API

Show Authentica certificates on your own website, app or custom account page, and keep them in step with refunds and ownership transfers.

The developer API lets your own systems read your certificates. Use it to show each customer their certificates on a custom account page, a WordPress site or a headless storefront, in your own design. Authentica keeps doing the work behind them: issuing, numbering, verifying, PDFs and ownership transfers.

What you can build

  • A "My certificates" section on your own website, with the product, size or colour, edition number, status and a link to the verification page.
  • A collection or vault page that shows everything a collector owns, including pieces transferred to them on resale.
  • An internal dashboard or ERP sync that mirrors every certificate and its status.
  • Automations that react the moment a certificate is revoked or changes owner, using webhooks.

Before you start

Quick start

  1. Create an API key

    In Authentica open Settings → Developer API and choose Create API key. The key starts with auth_live_ and is shown once, so copy it straight into your server configuration.
  2. Call the API from your server

    Send the key in the Authorization header: Authorization: Bearer auth_live_.... Ask for one customer's certificates with ?email=.
  3. Show the results

    Each certificate includes its product, edition, status and verifyUrl. Link your "View certificate" button to verifyUrl, which is where buyers download the PDF and transfer ownership.
curl "https://authentica.api.miko.co.nz/v1/[email protected]" \
  -H "Authorization: Bearer auth_live_..."

Base URL and versioning

Base URLhttps://authentica.api.miko.co.nz
Versionv1, in the path. Fields are only ever added to v1, never renamed or removed, so an integration you build today keeps working.
FormatJSON over HTTPS. Times are ISO 8601 in UTC.
Rate limit120 requests a minute per key. Plenty for loading a customer's account page on every visit.

Keep your key safe

  • Call the API from your server only. Never put the key in browser JavaScript, a mobile app or a public repository.
  • The key gives read access to all of your certificates. Show a customer only the certificates for their own signed-in email address.
  • If a key is exposed, choose Replace API key in Settings. The old key stops working immediately. Revoke key closes API access completely.
  • Authentica stores only a fingerprint of your key, never the key itself, so it can't be recovered. Lost keys are replaced, not looked up.

Next steps


Related articles

Not on Shopify yet?

Start a free Shopify trial, then add Miko apps when you are ready.

Set up your store in minutes and try it with your own products. Loyalty, wholesale pricing, AI descriptions and the rest of the Miko apps install in one click once your store is live.