Available, development access
Authentication
One header, HTTPS only, server side only.
Header formatPermalink to this section
Present the key in an x-api-key header on every request. Keys are not accepted as a query parameter, because query strings end up in proxy logs and browser history.
curl "$RIDDLE_API_BASE/v1/markets/kalshi/$MARKET_ID" \
-H "x-api-key: $RIDDLE_API_KEY"RotationPermalink to this section
- 1.Ask for a second key while the first is still active.
- 2.Deploy the new key to your secret store and let the change roll out.
- 3.Confirm your traffic has moved over to the new key.
- 4.Retire the old key. Retirement takes effect for new requests; in-flight requests complete.
Practices we expectPermalink to this section
- Server side only. Do not ship a key to a browser, a mobile binary or a notebook you share.
- Redact the x-api-key header everywhere you log requests, including error reporters and traces.
- One key per deployment target, so retiring a compromised key does not take down everything else.
- Treat a 401 as terminal, not retryable. Retrying an unauthorised request will not make it authorised.