TUMR DOCS
Authentication & API Keys
Secure your API integration with Secret Keys and JWT Bearer Tokens.
Tumr supports two modes of authentication: Secret API Keys for server-to-server integrations, and JWT Bearer tokens for interactive user sessions.
1. Secret API Keys (Server-to-Server) Secret API keys are designed for backend services, e-commerce plug-ins, and automated scheduling systems.
Send the key in the Authorization header (either the ApiKey or Bearer scheme works) or in the dedicated X-Tumr-API-Key header:
``http
Authorization: ApiKey tumr_live_...
http
X-Tumr-API-Key: tumr_live_...
API Key Prefix Conventions
- tumr_live_...: Production keys. Real charges and live dispatching apply.
- tumr_test_...: Test keys. Objects created with a test key are flagged as test data and do not trigger real-world dispatch or settlement.
**Keep your secret API keys private!** > Never expose your Secret API Key in client-side applications (React, iOS, Android, Vue) or public source code repositories. Always make API requests from a backend proxy or serverless function.
2. JWT Bearer Tokens (Dashboard & Mobile) Used by user-facing applications such as the Tumr dashboards and the Rider mobile app.
- Authenticate using the [Login Endpoint](/en/docs/api-reference/auth/):
- ```http
- POST /api/v1/auth/login/
- Content-Type: application/json
{ "email": "[email protected]", "password": "SecurePassword123!" } ```
- Use the returned
accesstoken in subsequent requests: - ```http
- Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
`
Access tokens expire after 60 minutes. Use the refresh token (valid for 7 days) with POST /api/v1/auth/refresh/ to obtain fresh credentials without prompting the user to re-authenticate.