Authentication
All endpoints require authentication via one of two methods: a third-party API key or a Firebase user token. Keys are scoped to specific permissions and can be restricted to individual hubs.
Authentication Methods
| Method | Header | Description |
|---|---|---|
| API Key | X-API-Key: vh_... |
Third-party API key authentication |
| Firebase | Authorization: Bearer <token> |
Firebase user authentication |
API Key Authentication
API keys are long-lived credentials prefixed with vh_. They are ideal for backend services, cron jobs, and third-party integrations where a human user is not present.
Where keys come from: TINA & operators
API keys are generated in TINA, the VenHub dashboard — there's no endpoint for creating one programmatically. Every VenHub partner gets their own TINA login.
Usage
Include your API key in the X-API-Key header on every request:
curl -X GET \ "https://tina-api.venhub.com/api/v1/owners/hub_inventory/?hub_id=123" \ --header "X-API-Key: vh_abc123your_key_here"
Key Format
All API keys follow the pattern vh_ followed by a random alphanumeric string. Keys are case-sensitive.
Permission Scopes
API keys are issued with one or more scopes that control which endpoints they can access. Follow the principle of least privilege — only grant the scopes your integration actually needs.
Key Expiration
API keys can be set with an optional expiration date. An expired key returns a 401 api_key_expired error. Keys without an expiration remain valid until revoked.
Firebase Authentication
Firebase user authentication is used for requests made on behalf of a signed-in VenHub user.
Usage
Include the Firebase ID token in the Authorization header on every request:
curl -X GET \ "https://tina-api.venhub.com/api/v1/owners/hub_inventory/?hub_id=123" \ --header "Authorization: Bearer <token>"
Authentication Errors
| Error Code | HTTP Status | Description |
|---|---|---|
| invalid_api_key | 401 | API key is missing, malformed, or has been revoked |
| api_key_expired | 401 | API key has passed its expiration date |
| scope_missing | 403 | API key does not have the required permission scope for this endpoint |
| hub_access_denied | 403 | API key is valid but does not have access to the requested hub |