Authentication

Every request carries your API key. There are no tokens to exchange or refresh.

API keys

RateMatch issues your keys when your partner account is set up: one for the sandbox and one for live. Each works only with its own server.

KeyServerCredit checks
rm_sandbox_…https://staging.api.ratematch.ai/api/partner/v1Simulated; no credit bureau is called
rm_live_…https://api.ratematch.ai/api/partner/v1Real soft checks with Equifax
A key acts as your partner account. Keep it on your server; never put it in a web page or mobile app, and don't commit it to source control. RateMatch shows a key only once, when it is issued.

Sending the key

Put it in the Authorization header of every request. GET /me is a quick way to check a key:

GET /me
curl https://staging.api.ratematch.ai/api/partner/v1/me \
  -H "Authorization: Bearer rm_sandbox_your_key"
200 OK
{ "success": true, "data": { "partnerId": "PID1288", "environment": "sandbox" } }

When a key is refused

StatuserrorMeaning
401UNAUTHORIZEDNo key, or the key is invalid or revoked.
401WRONG_ENVIRONMENTA sandbox key sent to the live server, or a live key sent to the sandbox.
403PARTNER_INACTIVEYour partner account is not active. Contact RateMatch.

Replacing a key

Ask RateMatch for a new key. Both keys work until you have switched over and asked for the old one to be revoked, so there is no downtime. If a key may have leaked, ask for it to be revoked straight away; it stops working immediately.