//Authentication & Headers

Authentication & HTTP Headers

To communicate with the ButtrBase API, you must provide specific HTTP headers with every request.

Mandatory Headers

1. Authorization

All protected endpoints require a valid JSON Web Token (JWT). This token is obtained upon successful login or registration.
  • Header Name: Authorization
  • Format: Bearer <your_access_token>
  • Example:
  • ~~~http Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... ~~~

    2. Content-Type

    For endpoints that accept a request body (typically POST, PUT, PATCH), you must specify the content type as JSON.
  • Header Name: Content-Type
  • Value: application/json

Custom Headers

Currently, the standard ButtrBase API relies solely on the Authorization header for identity verification. No custom headers (e.g., X-API-KEY) are required for standard client-side interactions, although server-side integrations might use organization API keys in the future.

Example Request

Here is a complete example of a curl request including headers:

~~~bash curl -X GET https://api.buttrbase.com/api/users/me \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" ~~~