Authentication and API Keys
One bearer token gives the REST API access to accounts, transfers and agent wallets. Each request has to include an API key issued by a Cyphron account.
Creating a key
You generate keys in the Developer section of the dashboard:
- Log in to Cyphron
- Open Dashboard → Developer → API Keys
- Click Generate New Key
- Give it a label, such as
production,devorinternal-tool - Store it securely right away, because you will only see it once
Each key is tied to the account that created it. A transfer sent through the API gets exactly the same confidentiality as one sent from the app. Privacy is not weakened just because a program is making the request.
Authenticating requests
Include the key in the Authorization header of each request:
Authorization: Bearer <your_api_key>
Here is a complete request:
curl -X POST https://api.usecyphron.com/v1/transfers \
-H "Authorization: Bearer hc_live_xxxxxxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"to": "@vendor",
"amount": "125.00",
"asset": "USDG",
"confidential": true,
"memo": "Invoice #4471"
}'
Live and test keys
| Prefix | Network | Use |
|---|---|---|
hc_live_ |
Mainnet | For production, where calls create real on-chain transactions |
hc_test_ |
Testnet | For development, with no need for real USDG |
Build your integration with test keys. Requests made with them go to the Robinhood Chain testnet (chain ID 46630), so they never reach mainnet (chain ID 4663) or move real money.
Key management
From the dashboard you can:
- List all of your keys along with when each was last used
- Revoke a key, which takes effect instantly
- Inspect usage for each key, including how many requests it made and how much USDG it moved
Keeping keys secure
- Store keys in environment variables or a secrets manager, and never commit them to source control.
- Rotate a key as soon as you think it may have leaked.
- Give each environment its own key.
- Revoke keys you no longer use.
Anyone holding a live key can send funds out of your account, so protect it with the same care as a private key.
What a key cannot do
An API key will never cause a transaction amount to be decrypted on the server for you. This limit is built into the system's design, not enforced by a rule someone could bend. If your integration needs to see a confidential amount, it has to decrypt it client-side using your account's decryption key, just like the Cyphron app.