The developer API lets your own systems read your certificates. Use it to show each customer their certificates on a custom account page, a WordPress site or a headless storefront, in your own design. Authentica keeps doing the work behind them: issuing, numbering, verifying, PDFs and ownership transfers.
What you can build
- A "My certificates" section on your own website, with the product, size or colour, edition number, status and a link to the verification page.
- A collection or vault page that shows everything a collector owns, including pieces transferred to them on resale.
- An internal dashboard or ERP sync that mirrors every certificate and its status.
- Automations that react the moment a certificate is revoked or changes owner, using webhooks.
Before you start
Quick start
Create an API key
In Authentica open Settings → Developer API and choose Create API key. The key starts withauth_live_and is shown once, so copy it straight into your server configuration.Call the API from your server
Send the key in theAuthorizationheader:Authorization: Bearer auth_live_.... Ask for one customer's certificates with?email=.Show the results
Each certificate includes its product, edition, status andverifyUrl. Link your "View certificate" button toverifyUrl, which is where buyers download the PDF and transfer ownership.
curl "https://authentica.api.miko.co.nz/v1/[email protected]" \
-H "Authorization: Bearer auth_live_..."
Base URL and versioning
| Base URL | https://authentica.api.miko.co.nz |
| Version | v1, in the path. Fields are only ever added to v1, never renamed or removed, so an integration you build today keeps working. |
| Format | JSON over HTTPS. Times are ISO 8601 in UTC. |
| Rate limit | 120 requests a minute per key. Plenty for loading a customer's account page on every visit. |
Keep your key safe
- Call the API from your server only. Never put the key in browser JavaScript, a mobile app or a public repository.
- The key gives read access to all of your certificates. Show a customer only the certificates for their own signed-in email address.
- If a key is exposed, choose Replace API key in Settings. The old key stops working immediately. Revoke key closes API access completely.
- Authentica stores only a fingerprint of your key, never the key itself, so it can't be recovered. Lost keys are replaced, not looked up.
Next steps
- API reference: every filter, field and error.
- Webhooks and signatures: get notified of changes instead of asking for them.
- WordPress and headless stores: a complete worked example.
Related articles