Authentication and API keys
Bearer API keys, scopes, the requirements on the key owner, expiry, rotation and revocation.
Public API status
The v1 API described here is implemented and tested, but api.remindcash.com is not yet open to the public. It opens after final acceptance testing; until then requests return 503. Examples use placeholders — never paste a real key into shared code.
Bearer keys
Send your key in the Authorization header of every request:
GET /v1/receivables HTTP/1.1
Host: api.remindcash.com
Authorization: Bearer <your-api-key>
Accept: application/jsonRequests without a valid key return 401 unauthenticated.
Scopes
Each key carries one or more scopes. A request outside the key's scopes returns 403 forbidden.
| Scope | Allows |
|---|---|
receivables:read |
GET /receivables, GET /receivables/{id}, GET /reminder-attempts |
receivables:write |
POST /receivables, PATCH /receivables/{id}, payments, pause, resume, cancel |
usage:read |
GET /usage |
payables:read, payables:write |
Reserved. No payables endpoints exist yet. |
Give each integration only the scopes it needs.
Who can use a key
A key acts on behalf of the person who created it, inside one company. Every request checks that:
- the key owner's email is verified and two-factor authentication is confirmed,
- the key owner is still an active member of the company,
- the company itself is active.
If any check fails, the request returns 403 forbidden. Removing a team member therefore stops their keys immediately.
Creating, rotating and revoking keys
Keys are managed in the app under Settings → API keys by company owners and admins with two-factor authentication.
- A new key is shown once; RemindCash stores only a hash of it.
- Keys expire 30 days after they are issued.
- Rotate issues a new key with the same name and scopes and deletes the old one immediately. Update your secret store before rotating.
- Revoke deletes a key immediately.
- Each person can hold up to 10 active keys per company.
Keeping keys safe
- Store keys in a secret manager or environment variable, never in source control or front-end code.
- Use separate keys for separate systems so you can revoke one without affecting the others.
- If a key may have leaked, revoke it in Settings straight away.