Authentication
Every request carries your API key. There are no tokens to exchange or refresh.
API keys
RateMatch issues your keys when your partner account is set up: one for the sandbox and one for live. Each works only with its own server.
| Key | Server | Credit checks |
|---|---|---|
rm_sandbox_… | https://staging.api.ratematch.ai/api/partner/v1 | Simulated; no credit bureau is called |
rm_live_… | https://api.ratematch.ai/api/partner/v1 | Real soft checks with Equifax |
A key acts as your partner account. Keep it on your server; never put it in a web page or mobile app, and don't commit it to source control. RateMatch shows a key only once, when it is issued.
Sending the key
Put it in the Authorization header of every request. GET /me is a quick way to check a key:
GET /me
curl https://staging.api.ratematch.ai/api/partner/v1/me \
-H "Authorization: Bearer rm_sandbox_your_key"200 OK
{ "success": true, "data": { "partnerId": "PID1288", "environment": "sandbox" } }When a key is refused
| Status | error | Meaning |
|---|---|---|
| 401 | UNAUTHORIZED | No key, or the key is invalid or revoked. |
| 401 | WRONG_ENVIRONMENT | A sandbox key sent to the live server, or a live key sent to the sandbox. |
| 403 | PARTNER_INACTIVE | Your partner account is not active. Contact RateMatch. |
Replacing a key
Ask RateMatch for a new key. Both keys work until you have switched over and asked for the old one to be revoked, so there is no downtime. If a key may have leaked, ask for it to be revoked straight away; it stops working immediately.