Every endpoint lives under /v1 on https://api.rheon.io and takes your API key
as a Bearer token. There is one kind of key: it carries your products, corridors,
rate and ceiling, and works from your server, a page, or the playground on these
pages alike. Treat it as a secret: anyone holding it acts under its permissions
until it is rotated.
Sending the key
The playground on these pages calls the live API with the key you paste. Crypto
deposits run on production and move real money once the transaction is signed.
There is no shared demo key: use your own, or copy the request into your backend.
Getting a key
We issue it. The key is shown once, at creation: we keep only a fingerprint of
it, so a lost key cannot be recovered, only replaced. Tell us and we will issue a
new one; the old one stops working the moment the new one is in place.
What the key may use
Read it from the API rather than asking us:
GET /v1/config answers
the products you may call, your maxExecutionUsd, and under crypto the chains
and tokens you may name. What each of those means for your integration, and why
a missing product is a refusal rather than a default, is on
Rheon API.
What a refusal looks like
Every refusal uses the one error envelope, described on Errors: