Authentication

Every call carries the API key as a bearer token in the Authorization header:

curl https://service.invoice-api.xhub.io/api/v1/invoice/formats \
-H "Authorization: Bearer sk_live_xxxxx"

Test and live mode

PrefixModeUsed for
sk_test_*TestDevelopment and integration tests
sk_live_*LiveProduction

The mode is part of the key itself — there is no separate switch and no second base URL.

Entitlements

What a key may do hangs on its entitlements:

  • pdf:{country}:generate — create a PDF
  • e-invoice:{country}:{format}:create — create an e-invoice
  • e-invoice:{country}:{format}:parse — read an e-invoice

If one is missing you get 403, not 401. A 401 means the key is absent, unknown or expired.

Quotas

Usage is counted per entitlement. Once a quota is spent, the API answers 429 and puts the details in the body.

API keys belong on your server, never in browser or mobile code. A key in the frontend is a published key.