Get your account
Developer API

Authentication and API Keys

Beta. Parts of what these docs describe are still being built. The roadmap shows what is live today.

One bearer token gives the REST API access to accounts, transfers and agent wallets. Each request has to include an API key issued by a Cyphron account.


Creating a key

You generate keys in the Developer section of the dashboard:

  1. Log in to Cyphron
  2. Open Dashboard → Developer → API Keys
  3. Click Generate New Key
  4. Give it a label, such as production, dev or internal-tool
  5. Store it securely right away, because you will only see it once

Each key is tied to the account that created it. A transfer sent through the API gets exactly the same confidentiality as one sent from the app. Privacy is not weakened just because a program is making the request.


Authenticating requests

Include the key in the Authorization header of each request:

Authorization: Bearer <your_api_key>

Here is a complete request:

curl -X POST https://api.usecyphron.com/v1/transfers \
  -H "Authorization: Bearer hc_live_xxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{
    "to": "@vendor",
    "amount": "125.00",
    "asset": "USDG",
    "confidential": true,
    "memo": "Invoice #4471"
  }'

Live and test keys

Prefix Network Use
hc_live_ Mainnet For production, where calls create real on-chain transactions
hc_test_ Testnet For development, with no need for real USDG

Build your integration with test keys. Requests made with them go to the Robinhood Chain testnet (chain ID 46630), so they never reach mainnet (chain ID 4663) or move real money.


Key management

From the dashboard you can:

  • List all of your keys along with when each was last used
  • Revoke a key, which takes effect instantly
  • Inspect usage for each key, including how many requests it made and how much USDG it moved

Keeping keys secure

  • Store keys in environment variables or a secrets manager, and never commit them to source control.
  • Rotate a key as soon as you think it may have leaked.
  • Give each environment its own key.
  • Revoke keys you no longer use.

Anyone holding a live key can send funds out of your account, so protect it with the same care as a private key.


What a key cannot do

An API key will never cause a transaction amount to be decrypted on the server for you. This limit is built into the system's design, not enforced by a rule someone could bend. If your integration needs to see a confidential amount, it has to decrypt it client-side using your account's decryption key, just like the Cyphron app.