Skip to main content

Authentication

The moncreneau API uses API keys to authenticate requests.

API Key Format​

moncreneau API keys follow a prefixed format starting with mk_ followed by alphanumeric characters.

Example: mk_abc123def456ghi789

Authenticating Requests​

Include your API key in the X-API-Key header:

curl https://mc-prd.duckdns.org/api/v1/departments -H "X-API-Key: YOUR_API_KEY"

Scope of API key authentication​

An API key (X-API-Key) only authenticates the public endpoints under /api/v1/** (appointments, departments, availability — documented in the API Reference section).

It grants access to nothing else. Managing your API keys themselves, configuring webhooks, and the usage dashboard (the API Keys, Webhooks, and Usage pages) are reserved for the MonCréneau web dashboard, authenticated by a staff login session — there is no way to reach them programmatically from a third-party application, with or without an API key.

API Key Security​

Important
  • Never commit your API keys to source code
  • Never share them publicly
  • Use environment variables to store them
  • Regenerate your keys if they are compromised

Best Practices​

.env
# ✅ Good
MONCRENEAU_API_KEY=mk_abc123...

# ❌ Bad: hardcoding in code
const apiKey = "mk_abc123...";

Authentication Errors​

CodeErrorDescription
401MISSING_API_KEYAuthorization header missing
401INVALID_API_KEYInvalid or revoked API key
403INSUFFICIENT_SCOPEInsufficient scope for operation

Next Steps​