CueDMDocs
Authentication

Get started

Authentication

Create a workspace API key, send it as a bearer token, and handle rate limits and errors.

API keys

Every API request carries a workspace API key. A key belongs to one workspace and can do what the API allows for that workspace, whoever created it. Keys look like cuedm_ followed by 43 characters.

  1. Create a key

    In Settings → Integrations, under API keys, choose Create key. Name it after what will use it, such as “Zapier” or “Warehouse sync”, so you know which one to revoke later.

  2. Copy it once

    CueDM shows the key once and stores only a hash of it. If you lose it, revoke it and create a new one.

  3. Keep it on the server

    Put it in an environment variable or your secrets manager. Never put it in a web page, a mobile app or a public repository: anyone with the key can manage your workspace's webhooks.

Studio plan

API keys are part of Studio. If the workspace moves to another plan, its keys are kept but refused with a 403. They work again as soon as the workspace is back on Studio. Webhooks set up in Settings keep working on every plan.

A workspace can have up to 10 active keys. The list in Settings shows when each key was last used (to the minute). Revoking a key stops it at once.

Sending the key

Send the key as a bearer token in the Authorization header. Keys in the query string or body are ignored.

curl https://cuedm.com/api/v1/me \
  -H "Authorization: Bearer cuedm_…"

A missing, mistyped or revoked key gets a 401 with a WWW-Authenticate: Bearer header. Requests with a bad key never count against a rate limit.

Rate limits

Each key can make 120 requests a minute. The window starts with the key's first request and resets a minute later. Each key has its own limit, so two keys in the same workspace get 120 each.

Over the limit, the API answers 429 with these headers. Wait for Retry-After seconds, then try again.

Retry-Afterseconds
How long until the window resets.
X-RateLimit-Limitinteger
Requests allowed per minute (120).
X-RateLimit-Remaininginteger
Requests left in this window.
X-RateLimit-ResetUnix seconds
When the window resets.

A normal Zapier or Make connection sends a few requests an hour. If you reach the limit, something is probably calling the API in a loop, often the sample endpoint.

Errors

Errors use ordinary HTTP status codes. The body always has success: false and an error you can show to a person. Validation errors may also include details.

401 Unauthorized
{
  "success": false,
  "error": "Send a workspace API key as Authorization: Bearer cuedm_…"
}
400Bad Request
The body is not valid JSON, or a field is missing or wrong. The error says which.
401Unauthorized
The key is missing, mistyped or revoked.
403Forbidden
The key is valid but the workspace is not on Studio.
404Not Found
No such resource, for example an unknown event name.
429Too Many Requests
Rate limited. Retry after the Retry-After header.
5xxServer error
Something failed on our side. Retry with backoff; if it continues, email support.

Stuck, or something here is wrong? Email support@cuedm.com and a person will answer.