Authentication
API key authentication for The Trade Hub API - creation, usage and security best practices.
All requests to The Trade Hub API must be authenticated using an API key passed via the X-API-Key HTTP header.
Getting an API key
API keys are created from your organization's developer dashboard:
- Sign in to your The Trade Hub account
- Open your organization from the Organizations area, then go to Developer
- Click Create API Key
- Name your key and select the required scopes (
classifyfor the EU,classify_chinafor China,export_controlfor export control)
Key format
All API keys use the th_live_ prefix followed by 32 random hexadecimal characters:
th_live_a1b2c3d4e5f60718293a4b5c6d7e8f90The prefix shown in the dashboard (th_live_xxxx) identifies the key without exposing its full value. The complete key is only visible at creation time.
Usage
Include your API key in the X-API-Key header of every request:
curl -X POST https://api.thetradehub.eu/v1/classify/jobs \
-H "X-API-Key: th_live_your_api_key" \
-H "Content-Type: application/json" \
-d '{"content": "Wireless Bluetooth headphones"}'Response for invalid key
If the API key is missing or invalid, the API returns a 401 Unauthorized error:
{
"error": "unauthorized"
}Security best practices
Never expose your key on the client side
Your API key must never appear in frontend code (browser JavaScript, mobile app). Always make API calls from your backend server.
Use environment variables
Store your keys in environment variables, never hardcoded in source code:
# .env
TRADEHUB_API_KEY=th_live_your_api_keyimport os
api_key = os.environ["TRADEHUB_API_KEY"]Regular rotation
Rotate your API keys regularly:
- Create a new key in the developer dashboard
- Update your systems with the new key
- Delete the old key once migration is complete
Least privilege
Create dedicated keys per service or application. In case of compromise, only the affected key needs to be revoked.
Monitoring
Monitor your API key activity from the dashboard. Unusual requests (abnormal volume, unused endpoints) may indicate a leak.
Last updated on