Authentication
Every data endpoint needs an API key. Discovery endpoints are public and need none: /v1/catalog, /v1/search, /v1/status, /v1/calendar, /v1/plans, /v1/commodities/items and /v1/commodities/cities.
Sending your key
The preferred way is the X-API-Key header:
curl -H "X-API-Key: pk_live_xxx" \
"https://api.pakdatahub.com/v1/series/rates.kibor.3m"
For quick tests, pandas read_csv or a spreadsheet import, you can pass it as a query parameter instead:
https://api.pakdatahub.com/v1/series/rates.kibor.3m?api_key=pk_live_xxx
Avoid the query-parameter form in production, because URLs end up in logs and browser history.
Key format and storage
- Keys start with
pk_live_. - A key is shown once, when it is created. We store only a hash, so a lost key can't be recovered; revoke it and create a new one.
- Each account can hold up to 3 active keys, for example one per environment. See
/v1/keys. - Each key's
last_used_atis recorded, updated at most once a minute, so you can spot unused keys.
Session tokens (dashboard)
The web dashboard signs you in with email and password or Google, and holds a session token. The account-management endpoints accept either credential:
| Endpoint | API key | Session token (X-Session-Token) |
|---|---|---|
/v1/series, /v1/funds, all data endpoints |
yes | no |
/v1/account, /v1/keys, /v1/usage, /v1/webhooks, /v1/billing/portal |
yes | yes |
See Auth endpoints for signup, login and logout.
What happens when a key is wrong
{ "success": false, "error": { "code": "unauthorized", "message": "missing API key" } }
A missing or invalid key returns 401 unauthorized. The other auth-related errors are:
402: this month's free calls are used up, or the subscription is inactive.403: the feature needs a higher plan (e.g. revision vintages need Pro).
See Errors & rate limits.
Rotating a key
- Create a new key (
POST /v1/keysor the dashboard). - Deploy it.
- Revoke the old one (
DELETE /v1/keys/{id}).
Revocation takes effect immediately.