Authentication
Every call carries the API key as a bearer token in the Authorization header:
Test and live mode
The mode is part of the key itself — there is no separate switch and no second base URL.
Entitlements
What a key may do hangs on its entitlements:
pdf:{country}:generate— create a PDFe-invoice:{country}:{format}:create— create an e-invoicee-invoice:{country}:{format}:parse— read an e-invoice
If one is missing you get 403, not 401. A 401 means the key is absent,
unknown or expired.
Quotas
Usage is counted per entitlement. Once a quota is spent, the API answers 429
and puts the details in the body.
API keys belong on your server, never in browser or mobile code. A key in the frontend is a published key.
