Start Here

Authentication

Every request to /v1 carries an API key as a bearer token. Keys belong to a workspace, so everything you create with one — codes, broadcasts, webhook events — is scoped to that workspace.

Sending your key

Put the key in the Authorization header. Keys start with transmit_live_ followed by 64 hex characters.

curl https://api.transmitinfra.com/v1/broadcast/5b1e7c2a-9f04-4c3e-8a61-2d7f0e9b4c18 \
  -H "Authorization: Bearer $TRANSMIT_API_KEY"

The samples read the key from a TRANSMIT_API_KEY environment variable. Keep it there, or in your secret manager — never in source control or browser code.

Managing keys

Keys are created and revoked on the API Keys page of the dashboard.

  • Shown once: Only a hash and a short prefix are stored. A lost key cannot be recovered — create a new one and revoke the old.
  • Ten active keys: A workspace holds at most ten active keys. Revoke one to free a slot.
  • Instant revocation: Every request checks the key against the database, so a revoked key fails on its very next call.
  • Last used: Usage is recorded at hourly resolution — enough to tell whether anything still calls a key before you revoke it.

When authentication fails

Every failure is 401 with the code UNAUTHORIZED. The message tells you whether the header was missing or malformed, but an unknown key, a revoked key and a key from a deactivated workspace all get the same answer.

// no header, or not a Bearer token
{ "error": { "message": "Missing authorization header. Use Bearer transmit_live_...", "code": "UNAUTHORIZED" } }

// not shaped like a Transmit key
{ "error": { "message": "Invalid API key format", "code": "UNAUTHORIZED" } }

// unknown, revoked, or the workspace is deactivated
{ "error": { "message": "Invalid or missing API key", "code": "UNAUTHORIZED" } }
Branch on code, not on message. Message wording can change; codes are the contract.