Command Palette
Search for a command to run...
Authentication
API authentication and key management
Enterprise-Grade Authentication
LeakZero implements military-grade API authentication using cryptographically secure key-based authentication with timestamp validation, ensuring maximum security for your breach intelligence operations.Getting Started with API Authentication
API Key Management
Generate and manage your API authentication credentials
Authentication Methods
API Key Authentication
Primary authentication method using secure API keys
Required Headers
x-api-keyYour API keyx-timestampISO 8601 timestampx-request-idUnique request identifierContent-Typeapplication/jsonCryptographically secure key generation
Request-level timestamp validation
Unique request ID tracking
Authentication Examples
cURL
curl -X POST "https://api.leakzero.io/api/v1/public/search/regular" \
-H "x-api-key: YOUR_API_KEY_HERE" \
-H "x-timestamp: 2024-01-15T10:30:00Z" \
-H "x-request-id: req_1705315800_abcd1234" \
-H "Content-Type: application/json" \
-d '{
"field": "email",
"value": "[email protected]",
"option": "exact",
"rowLimit": 100
}'TypeScript
// TypeScript Authentication Example
const LEAKZERO_API_KEY = process.env.LEAKZERO_API_KEY;
const generateHeaders = (): Record<string, string> => {
return {
'x-api-key': LEAKZERO_API_KEY!,
'x-timestamp': new Date().toISOString(),
'x-request-id': `req_${Date.now()}_${Math.random().toString(36).substr(2, 8)}`,
'Content-Type': 'application/json',
'User-Agent': 'LeakZero-Client/1.0.0'
};
};
const makeAuthenticatedRequest = async (endpoint: string, data?: any) => {
const response = await fetch(`https://api.leakzero.io/api/v1${endpoint}`, {
method: data ? 'POST' : 'GET',
headers: generateHeaders(),
body: data ? JSON.stringify(data) : undefined,
});
if (!response.ok) {
throw new Error(`API request failed: ${response.status}`);
}
return response.json();
};JavaScript
// JavaScript Authentication Example
const LEAKZERO_API_KEY = process.env.LEAKZERO_API_KEY;
function generateHeaders() {
return {
'x-api-key': LEAKZERO_API_KEY,
'x-timestamp': new Date().toISOString(),
'x-request-id': `req_${Date.now()}_${Math.random().toString(36).substr(2, 8)}`,
'Content-Type': 'application/json',
'User-Agent': 'LeakZero-Client/1.0.0'
};
}
async function makeAuthenticatedRequest(endpoint, data) {
const response = await fetch(`https://api.leakzero.io/api/v1${endpoint}`, {
method: data ? 'POST' : 'GET',
headers: generateHeaders(),
body: data ? JSON.stringify(data) : undefined,
});
if (!response.ok) {
throw new Error(`API request failed: ${response.status}`);
}
return response.json();
}Python
# Python Authentication Example
import os
import json
import time
import uuid
from datetime import datetime
import requests
class LeakZeroAuth:
def __init__(self, api_key=None):
self.api_key = api_key or os.getenv('LEAKZERO_API_KEY')
if not self.api_key:
raise ValueError("API key is required")
self.base_url = "https://api.leakzero.io/api/v1"
def generate_headers(self):
return {
'x-api-key': self.api_key,
'x-timestamp': datetime.utcnow().isoformat() + 'Z',
'x-request-id': f"req_{int(time.time())}_{str(uuid.uuid4())[:8]}",
'Content-Type': 'application/json',
'User-Agent': 'LeakZero-Python-Client/1.0.0'
}
def make_authenticated_request(self, endpoint, data=None):
url = f"{self.base_url}{endpoint}"
headers = self.generate_headers()
if data:
response = requests.post(url, headers=headers, json=data)
else:
response = requests.get(url, headers=headers)
response.raise_for_status()
return response.json()
# Usage
client = LeakZeroAuth()
result = client.make_authenticated_request('/public/balance')Security Best Practices
Do's
- Store API keys in environment variables
- Use HTTPS for all API requests
- Implement proper error handling
- Monitor API usage and costs
- Rotate API keys regularly
Don'ts
- Never commit API keys to version control
- Don't share API keys in plain text
- Avoid hardcoding keys in client-side code
- Don't use API keys in URLs or logs
- Never disable SSL/TLS verification
Error Handling
Common Authentication Errors
Handle authentication errors gracefully in your applications
401 Unauthorized
Invalid or missing API key. Check your authentication headers.
403 Forbidden
API key valid but insufficient permissions for requested operation.
429 Too Many Requests
Rate limit exceeded. Implement exponential backoff.