Start
Get integrated in five minutes
Three things before you write any code:
- Which header carries the key. It differs by service, see the table below.
- Sandbox and production are separate hosts with separate credentials. A sandbox key does not work against production and vice versa. See Environments for the host list.
- Where to get credentials. From your IDCanopy contact. There is no self-service signup on this portal yet, pending.
Auth header by service
| Service | How the key travels |
|---|---|
| Umbrella API | Api-Key + Customer-Id headers to POST /auth, which returns a bearer token. Use Authorization: Bearer <token> on every subsequent call. |
| Aletheia (forensic scoring) | Authorization: Bearer <token> per tenant. No separate token-exchange call. |
| AutoKYB | pending |
Full detail: Authentication.
Next
- Authentication, the token exchange, step by step
- Environments, every base URL, production and sandbox
- First call, the curl pair against sandbox and its verification status