Skip to main content

Authentication

The Eaternity API uses Basic Authentication with your API key to secure all requests.

Overview​

RequirementDetails
Authentication TypeHTTP Basic Auth
UsernameYour API key
PasswordEmpty (leave blank)
ProtocolHTTPS only (SSL/TLS required)
SNI SupportServer Name Indication required

Getting Your API Key​

To obtain an API key:

  1. Contact Eaternity — Email: info@eaternity.ch. Include your company name, use case, and estimated request volume.
  2. Receive API Key — You'll receive a unique API key via secure email.
  3. Activate License — Your API key will be associated with licensed kitchen(s). Unlicensed kitchens will return 403 Forbidden errors.
Keep Your API Key Secret

Your API key grants access to your data and incurs usage charges. Never share it publicly or commit it to version control.

Authentication Methods​

cURL​

Use the -u flag with your API key as the username and an empty password (note the colon):

curl -u YOUR_API_KEY: https://co2.eaternity.ch/api/kitchens/

HTTP Header​

Manually construct the Basic Auth header:

# Base64 encode "YOUR_API_KEY:"
echo -n "YOUR_API_KEY:" | base64
# Result: WU9VUl9BUElfS0VZOg==

curl -H "Authorization: Basic WU9VUl9BUElfS0VZOg==" \
https://co2.eaternity.ch/api/kitchens/

Python​

import requests

API_KEY = "YOUR_API_KEY"
BASE_URL = "https://co2.eaternity.ch/api"

# Method 1: Using auth parameter
response = requests.get(
f"{BASE_URL}/kitchens/",
auth=(API_KEY, "")
)

# Method 2: Using headers
import base64
auth_header = base64.b64encode(f"{API_KEY}:".encode()).decode()
response = requests.get(
f"{BASE_URL}/kitchens/",
headers={"Authorization": f"Basic {auth_header}"}
)

JavaScript (Node.js)​

// Using fetch with Buffer (Node.js)
const API_KEY = 'YOUR_API_KEY';
const BASE_URL = 'https://co2.eaternity.ch/api';

const authHeader = Buffer.from(`${API_KEY}:`).toString('base64');

fetch(`${BASE_URL}/kitchens/`, {
headers: {
'Authorization': `Basic ${authHeader}`,
'Content-Type': 'application/json'
}
})
.then(response => response.json())
.then(data => console.log(data));

SSL/TLS Requirements​

All API requests must use HTTPS. The API server requires Server Name Indication (SNI) support — most modern HTTP libraries handle this by default. See the SSL & SNI section on the introduction page for details.

Rate Limiting​

Contact info@eaternity.ch for details on rate limit policies for your API key.

Error Responses​

Authentication errors return standard HTTP status codes. See the HTTP Status Codes section on the introduction page for details on all error codes including 401 Unauthorized and 403 Forbidden.

Security Best Practices​

Environment Variables​

Store API keys in environment variables, not in code:

# .env file (add to .gitignore)
EATERNITY_API_KEY=your_actual_api_key_here
import os
from dotenv import load_dotenv

load_dotenv()
API_KEY = os.getenv('EATERNITY_API_KEY')

API Key Rotation​

Rotate your API keys periodically:

  1. Request a new API key from support
  2. Update your applications with the new key
  3. Verify functionality with the new key
  4. Request deactivation of the old key

Endpoints​

Authentication endpoints including OAuth2 token exchange.

See OAuth 2 Token for the token exchange endpoint.