Domain-locked keys · Signed responses

API keys that only work
where you say —
and nowhere else.

Issue keys bound to your domain, verify every call through a signed gateway, and keep the substance of your site on our servers rather than in code anyone can copy. Built for teams shipping in fintech, commerce, CRM and 30 more verticals.

Domain-lockedKeys bound to your site
HMAC-signedTamper-evident replies
2FA + audit logOn every account
Rate-limitedPer-key call ceilings
buildapi — live request
Verdict
authorized
Domain
locked
Signature
valid
Example response illustrative
Core Platform

Key infrastructure, not another SDK.

Everything around the keys your product already needs — issuing, locking, verifying, metering and protecting them — across 34 industry verticals.

Domain-Locked Keys

Every key is bound to one domain and its subdomains. A key lifted from your page still only works on your site.

Secrets Never Stored Raw

Server keys are kept only as a peppered hash. Passwords use bcrypt. Traffic is TLS.

Protected Content

Serve copy, config and markup from us at runtime. A copied site has nothing to strip — it simply comes up empty.

Live

Quotas & Rate Limits

Monthly allowances and per-minute ceilings enforced at the gateway, with usage you can actually see.

How it works

One call. Verified end to end.

Your server asks whether a key is good for this domain, scope and quota. We answer in milliseconds, signed, so you can prove the reply came from us.

</> Your App 1 API call B BuildAPI auth · encrypt · route 🏦 Banking settlements · cards 🛒 Commerce orders · inventory 👥 CRM customers · events
Bank-grade security

Secrets we never store.
Replies you can verify.

Every request is authenticated, encrypted and logged. We hold ourselves to the same standard as the banks we connect to — and we can prove it.

  • Hashed Secrets & TLS

    Server keys stored as a peppered hash, bcrypt passwords, TLS in transit.

  • RBAC & 2FA

    Fine-grained permissions and optional two-factor on every account.

  • Immutable Audit Logs

    Every call, login and change tracked and tamper-proof.

  • GDPR tooling

    Self-service data export and account erasure, built in.

Who it's for

Financial infrastructure for every industry

Handle transactions, streamline operations and embed financial services — seamlessly.

For Marketplaces

Issue a key per storefront, locked to its own domain, metered separately.

For SaaS Platforms

Give each customer a scoped key, and revoke or rotate it without a deploy.

For Fintech Teams

Signed, nonce-bound verification and an immutable audit trail of every call.

For Agencies

Ship client sites that keep working for the client — and stop working if copied elsewhere.

FAQ

Questions, answered.

Everything you need to know to get started with confidence.

Talk to an expert

Do you charge any undisclosed fees?

No. Our pricing is transparent — you pay the advertised rate. No setup fees, no hidden charges.

How fast can I integrate?

Most teams ship their first live call in under an hour with our SDKs, OpenAPI specs and copy-paste examples.

Is my data secure?

TLS 1.3 in transit, bcrypt-hashed passwords, and server API keys stored only as a peppered hash — never in plaintext. Plus role-based access, two-factor authentication and an immutable audit log.

Ship in minutes.
Scale for years.

Join thousands of developers building on production-ready infrastructure. Your first API key is free.