Authentication header
Include your API key in theX-API-Key header:
Verifying your key
Error responses
Missing API key
Invalid API key
Insufficient permissions
Key prefixes
For detailed authentication setup, see the Authentication Guide.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
API authentication reference for the Hey Chocolate GraphQL API.
X-API-Key header:
curl -X POST https://api.heychocolate.com/graphql \
-H "Content-Type: application/json" \
-H "X-API-Key: sk_live_your_key_here" \
-d '{"query": "{ me { id name tier } }"}'
query {
me {
id
name
email
organization {
id
name
tier
}
apiKey {
prefix
createdAt
lastUsedAt
permissions
}
}
}
{
"errors": [
{
"message": "Authentication required. Provide a valid API key via the X-API-Key header.",
"extensions": { "code": "UNAUTHENTICATED" }
}
]
}
{
"errors": [
{
"message": "Invalid API key.",
"extensions": { "code": "INVALID_API_KEY" }
}
]
}
{
"errors": [
{
"message": "Your API key does not have permission to access this resource. Required tier: Growth",
"extensions": { "code": "FORBIDDEN", "requiredTier": "GROWTH" }
}
]
}
| Prefix | Environment |
|---|---|
sk_live_ | Production |
sk_sandbox_ | Sandbox |