Command Palette

Search for a command to run...

Authentication

API authentication and key management

Enterprise-Grade Authentication
LeakZero implements military-grade API authentication using cryptographically secure key-based authentication with timestamp validation, ensuring maximum security for your breach intelligence operations.

Getting Started with API Authentication

API Key Management
Generate and manage your API authentication credentials
1

Navigate to Dashboard

Go to Dashboard 🡒 API Access in your account

2

Generate API Key

Your first API key is automatically generated

3

Secure Storage

Store your API key securely in your application

Balance Management
Fund your API account for breach intelligence access

Top Up API Balance

Add funds directly to your API balance via Dashboard 🡒 Billing

Transfer Balance

Convert regular account balance to API balance instantly

Monitor Usage

Track API consumption and balance in real-time

Authentication Methods

API Key Authentication
Primary authentication method using secure API keys

Required Headers

x-api-keyYour API key
x-timestampISO 8601 timestamp
x-request-idUnique request identifier
Content-Typeapplication/json
Cryptographically secure key generation
Request-level timestamp validation
Unique request ID tracking

Authentication Examples

cURL
curl -X POST "https://api.leakzero.io/api/v1/public/search/regular" \
  -H "x-api-key: YOUR_API_KEY_HERE" \
  -H "x-timestamp: 2024-01-15T10:30:00Z" \
  -H "x-request-id: req_1705315800_abcd1234" \
  -H "Content-Type: application/json" \
  -d '{
    "field": "email",
    "value": "[email protected]",
    "option": "exact",
    "rowLimit": 100
  }'
TypeScript
// TypeScript Authentication Example
const LEAKZERO_API_KEY = process.env.LEAKZERO_API_KEY;

const generateHeaders = (): Record<string, string> => {
  return {
    'x-api-key': LEAKZERO_API_KEY!,
    'x-timestamp': new Date().toISOString(),
    'x-request-id': `req_${Date.now()}_${Math.random().toString(36).substr(2, 8)}`,
    'Content-Type': 'application/json',
    'User-Agent': 'LeakZero-Client/1.0.0'
  };
};

const makeAuthenticatedRequest = async (endpoint: string, data?: any) => {
  const response = await fetch(`https://api.leakzero.io/api/v1${endpoint}`, {
    method: data ? 'POST' : 'GET',
    headers: generateHeaders(),
    body: data ? JSON.stringify(data) : undefined,
  });

  if (!response.ok) {
    throw new Error(`API request failed: ${response.status}`);
  }

  return response.json();
};
JavaScript
// JavaScript Authentication Example
const LEAKZERO_API_KEY = process.env.LEAKZERO_API_KEY;

function generateHeaders() {
  return {
    'x-api-key': LEAKZERO_API_KEY,
    'x-timestamp': new Date().toISOString(),
    'x-request-id': `req_${Date.now()}_${Math.random().toString(36).substr(2, 8)}`,
    'Content-Type': 'application/json',
    'User-Agent': 'LeakZero-Client/1.0.0'
  };
}

async function makeAuthenticatedRequest(endpoint, data) {
  const response = await fetch(`https://api.leakzero.io/api/v1${endpoint}`, {
    method: data ? 'POST' : 'GET',
    headers: generateHeaders(),
    body: data ? JSON.stringify(data) : undefined,
  });

  if (!response.ok) {
    throw new Error(`API request failed: ${response.status}`);
  }

  return response.json();
}
Python
# Python Authentication Example
import os
import json
import time
import uuid
from datetime import datetime
import requests

class LeakZeroAuth:
    def __init__(self, api_key=None):
        self.api_key = api_key or os.getenv('LEAKZERO_API_KEY')
        if not self.api_key:
            raise ValueError("API key is required")

        self.base_url = "https://api.leakzero.io/api/v1"

    def generate_headers(self):
        return {
            'x-api-key': self.api_key,
            'x-timestamp': datetime.utcnow().isoformat() + 'Z',
            'x-request-id': f"req_{int(time.time())}_{str(uuid.uuid4())[:8]}",
            'Content-Type': 'application/json',
            'User-Agent': 'LeakZero-Python-Client/1.0.0'
        }

    def make_authenticated_request(self, endpoint, data=None):
        url = f"{self.base_url}{endpoint}"
        headers = self.generate_headers()

        if data:
            response = requests.post(url, headers=headers, json=data)
        else:
            response = requests.get(url, headers=headers)

        response.raise_for_status()
        return response.json()

# Usage
client = LeakZeroAuth()
result = client.make_authenticated_request('/public/balance')

Security Best Practices

Do's
  • Store API keys in environment variables
  • Use HTTPS for all API requests
  • Implement proper error handling
  • Monitor API usage and costs
  • Rotate API keys regularly
Don'ts
  • Never commit API keys to version control
  • Don't share API keys in plain text
  • Avoid hardcoding keys in client-side code
  • Don't use API keys in URLs or logs
  • Never disable SSL/TLS verification

Error Handling

Common Authentication Errors
Handle authentication errors gracefully in your applications
401 Unauthorized
Invalid or missing API key. Check your authentication headers.
403 Forbidden
API key valid but insufficient permissions for requested operation.
429 Too Many Requests
Rate limit exceeded. Implement exponential backoff.
Documentation - LeakZero | LeakZero