Skip to content
TUMR DOCS
Docsgetting startedAuthentication & API Keys

Authentication & API Keys

Secure your API integration with Secret Keys and JWT Bearer Tokens.

Tumr supports two modes of authentication: Secret API Keys for server-to-server integrations, and JWT Bearer tokens for interactive user sessions.

1. Secret API Keys (Server-to-Server) Secret API keys are designed for backend services, e-commerce plug-ins, and automated scheduling systems.

Send the key in the Authorization header (either the ApiKey or Bearer scheme works) or in the dedicated X-Tumr-API-Key header: ``http Authorization: ApiKey tumr_live_... http X-Tumr-API-Key: tumr_live_...

API Key Prefix Conventions - tumr_live_...: Production keys. Real charges and live dispatching apply. - tumr_test_...: Test keys. Objects created with a test key are flagged as test data and do not trigger real-world dispatch or settlement.

**Keep your secret API keys private!** > Never expose your Secret API Key in client-side applications (React, iOS, Android, Vue) or public source code repositories. Always make API requests from a backend proxy or serverless function.

2. JWT Bearer Tokens (Dashboard & Mobile) Used by user-facing applications such as the Tumr dashboards and the Rider mobile app.

  1. Authenticate using the [Login Endpoint](/en/docs/api-reference/auth/):
  2. ```http
  3. POST /api/v1/auth/login/
  4. Content-Type: application/json

{ "email": "[email protected]", "password": "SecurePassword123!" } ```

  1. Use the returned access token in subsequent requests:
  2. ```http
  3. Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
  4. `

Access tokens expire after 60 minutes. Use the refresh token (valid for 7 days) with POST /api/v1/auth/refresh/ to obtain fresh credentials without prompting the user to re-authenticate.