Authentication
Token exchange for Umbrella API, and the header for Aletheia
Umbrella API: token exchange
POST /auth (base URL: see Environments) with your key in headers, not
in the body:
curl -X POST "$UMBRELLA_BASE_URL/auth" \
-H "Api-Key: $UMBRELLA_API_KEY" \
-H "Customer-Id: $UMBRELLA_CUSTOMER_ID" \
-H "Content-Type: application/x-www-form-urlencoded"Response:
{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"expires_in": 3600,
"token_type": "Bearer"
}expires_in is in seconds (3600 = 1 hour). Use the token as
Authorization: Bearer <access_token> on every subsequent Umbrella API call. Re-authenticate
before it expires; there is no refresh-token flow.
Aletheia (forensic scoring)
No token exchange. Use your issued key directly:
curl "$ALETHEIA_BASE_URL/..." \
-H "Authorization: Bearer $ALETHEIA_API_KEY"IBAN Validation and Address Autocomplete are part of Umbrella API and use the same bearer token. AutoKYB: pending.