Skip to main content
Every request is authenticated with a single API key (pag_...). There is no token exchange: send the key directly as the Bearer token.
Prerequisite: an API key (pag_...) provided by the PagAmerican team. It is shown only once at creation. Store it securely.

Using your key

Send the key in the Authorization header on every request:
That’s it: there is no login or /auth call. The key carries your identity and scope, so you only ever receive the data that belongs to your account.

Security best practices

Treat the key like a password

Never expose your pag_ key in frontend code, public repositories, or logs. It grants full read access to your account’s data.

Always HTTPS

All calls must use HTTPS. Plain HTTP requests fail.

One key, reused

Send the same key on every request. There is no per-request token to generate.

Rotate if leaked

If you suspect a leak, ask the PagAmerican team to revoke the key and issue a new one. Revoked keys stop working immediately.

Rate limits

Requests are rate limited per key. When you exceed the limit you get 429 with a Retry-After header. Wait that many seconds, then retry. Reuse one key rather than requesting new ones.