Authentication
The moncreneau API uses API keys to authenticate requests.
API Key Format
moncreneau API keys follow a prefixed format starting with mk_ followed by alphanumeric characters.
Example: mk_abc123def456ghi789
Authenticating Requests
Include your API key in the X-API-Key header:
curl https://mc-prd.duckdns.org/api/v1/departments -H "X-API-Key: YOUR_API_KEY"
Scope of API key authentication
An API key (X-API-Key) only authenticates the public endpoints under /api/v1/** (appointments, departments, availability — documented in the API Reference section).
It grants access to nothing else. Managing your API keys themselves, configuring webhooks, and the usage dashboard (the API Keys, Webhooks, and Usage pages) are reserved for the MonCréneau web dashboard, authenticated by a staff login session — there is no way to reach them programmatically from a third-party application, with or without an API key.
API Key Security
Important
- Never commit your API keys to source code
- Never share them publicly
- Use environment variables to store them
- Regenerate your keys if they are compromised
Best Practices
.env
# ✅ Good
MONCRENEAU_API_KEY=mk_abc123...
# ❌ Bad: hardcoding in code
const apiKey = "mk_abc123...";
Authentication Errors
| Code | Error | Description |
|---|---|---|
401 | MISSING_API_KEY | Authorization header missing |
401 | INVALID_API_KEY | Invalid or revoked API key |
403 | INSUFFICIENT_SCOPE | Insufficient scope for operation |