Authentication & API Keys
The Cert-IX Scan API uses API keys for programmatic access. API keys provide granular scopes, scan type restrictions, per-key rate limits, IP allowlisting, automatic expiration, and zero-downtime rotation.
Authentication Methods​
| Method | Use Case | Header |
|---|---|---|
| API Key | Programmatic API access (scripts, CI/CD, integrations) | X-API-Key |
| JWT | Dashboard operations (API key management) | Authorization: Bearer <token> |
This page covers API key authentication. JWT authentication is handled automatically by the Cert-IX Dashboard.
API Key Format​
Cert-IX API keys follow a deterministic format for easy identification:
cix_sk_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
| Segment | Description |
|---|---|
cix_ | Cert-IX platform prefix |
sk_ | Secret key type identifier |
XXX... | 40-character cryptographic random string |
API keys are hashed with SHA-256 before storage. The raw key is displayed only once at creation. Cert-IX cannot retrieve your key if lost — you must rotate.
Passing Your API Key​
Include your API key in the X-API-Key header on every request:
curl -X GET https://api.cert-ix.com/scan-api/api/v1/scans \
-H "X-API-Key: cix_sk_your_api_key_here"
Query strings may be logged in server access logs, browser history, and proxy caches.
Creating an API Key​
API keys are created via the Cert-IX Dashboard (JWT authentication).