API keys that only work
where you say —
and nowhere else.
Issue keys bound to your domain, verify every call through a signed gateway, and keep the substance of your site on our servers rather than in code anyone can copy. Built for teams shipping in fintech, commerce, CRM and 30 more verticals.
Key infrastructure, not another SDK.
Everything around the keys your product already needs — issuing, locking, verifying, metering and protecting them — across 34 industry verticals.
Domain-Locked Keys
Every key is bound to one domain and its subdomains. A key lifted from your page still only works on your site.
Secrets Never Stored Raw
Server keys are kept only as a peppered hash. Passwords use bcrypt. Traffic is TLS.
Protected Content
Serve copy, config and markup from us at runtime. A copied site has nothing to strip — it simply comes up empty.
Quotas & Rate Limits
Monthly allowances and per-minute ceilings enforced at the gateway, with usage you can actually see.
One call. Verified end to end.
Your server asks whether a key is good for this domain, scope and quota. We answer in milliseconds, signed, so you can prove the reply came from us.
Secrets we never store.
Replies you can verify.
Every request is authenticated, encrypted and logged. We hold ourselves to the same standard as the banks we connect to — and we can prove it.
-
Hashed Secrets & TLS
Server keys stored as a peppered hash, bcrypt passwords, TLS in transit.
-
RBAC & 2FA
Fine-grained permissions and optional two-factor on every account.
-
Immutable Audit Logs
Every call, login and change tracked and tamper-proof.
-
GDPR tooling
Self-service data export and account erasure, built in.
Financial infrastructure for every industry
Handle transactions, streamline operations and embed financial services — seamlessly.
For Marketplaces
Issue a key per storefront, locked to its own domain, metered separately.
For SaaS Platforms
Give each customer a scoped key, and revoke or rotate it without a deploy.
For Fintech Teams
Signed, nonce-bound verification and an immutable audit trail of every call.
For Agencies
Ship client sites that keep working for the client — and stop working if copied elsewhere.
Questions, answered.
Everything you need to know to get started with confidence.
Talk to an expertDo you charge any undisclosed fees?
No. Our pricing is transparent — you pay the advertised rate. No setup fees, no hidden charges.
How fast can I integrate?
Most teams ship their first live call in under an hour with our SDKs, OpenAPI specs and copy-paste examples.
Is my data secure?
TLS 1.3 in transit, bcrypt-hashed passwords, and server API keys stored only as a peppered hash — never in plaintext. Plus role-based access, two-factor authentication and an immutable audit log.
Ship in minutes.
Scale for years.
Join thousands of developers building on production-ready infrastructure. Your first API key is free.