Authentication
Conversion endpoints require a Bearer API key. Discovery endpoints (/v1/categories,/v1/units,/v1/health,/openapi.json) are public.
Authorization header
http
Authorization: Bearer uu_live_xxxxxxxxxxxxxxxxxxxxxxxxxxKey format. Production keys use the
uu_live_ prefix and contain 32 cryptographically random bytes. Treat them like passwords.Do not embed API keys in public browser or mobile code.Use keys server-side only, or call public discovery endpoints without authentication.
Endpoint access table
| Endpoint | Authentication |
|---|---|
GET /v1/convert | Bearer |
POST /v1/convert | Bearer |
POST /v1/batch | Bearer |
GET /v1/categories | Public |
GET /v1/categories/:category | Public |
GET /v1/units | Public |
GET /v1/units/:unit | Public |
GET /v1/health | Public |
GET /openapi.json | Public |
Key rotation
- Open your account page and rotate the key
- Deploy your service with the new key
- Verify traffic is flowing correctly
- Confirm the previous key is revoked
Use separate keys for separate environments. Never reuse a key across production and development.