401.
Scopes
Each key carries a set of scopes, and every endpoint requires exactly one. Calling an endpoint your key has no scope for is a403. We grant scopes per partner; ask us if you need one you don’t have.
Account actions (
read:account, rip:packs, sell:cards, write:listings) also need the key to be linked to a CatchBack account. An unlinked key gets a 403 on them.
Keeping your key safe
- Keep it server-side only. Never put it in browser, mobile or other client code.
- Store it in a secret manager, not in source control.
- Rotate it when someone with access leaves your team.
- If it leaks, tell us immediately at catchbackcards@gmail.com. Keys are revoked individually, within minutes, without affecting your other keys.

