Authorization header:
Keys and modes
A key’s prefix tells you its mode:
The rest of the key is 43 random characters and a 6-character checksum, so secret scanners (GitHub’s included) can recognize a leaked key. We store only a SHA-256 hash: a lost key can’t be recovered, so revoke it and create a new one.
Getting a key
- Bridgeline turns on API access for your agency. During the beta this is by invitation; ask your Bridgeline contact. Live keys and test keys are enabled separately: ask your Bridgeline contact to enable test mode if you want test keys.
- An agency admin opens API Keys in the Bridgeline portal and creates a key: its mode (live or test), name, type, default broker, scopes and an optional expiry date.
- The full key is shown once. Copy it into your secret manager.
Key types
Every request acts as one of your agency’s active brokers, so every quote has a named owner in Bridgeline, just as it does in the portal.Acting as a broker
Write requests that create something take an optionalbroker_email in the JSON body. Today that’s POST /v1/quotes:
- Agency key: any active broker at your agency. Leave it out and the request acts as the key’s default broker. Set it from the logged-in user in your system, so each quote lands with the right producer.
- Broker key: leave it out, or send the key’s own broker. Naming anyone else returns
403 ACTING_BROKER_NOT_ALLOWED. - An email that isn’t an active broker at your agency returns
403 BROKER_NOT_ACTIVE. We give the same answer whether the person is inactive or works somewhere else. - Reads, and requests with no body, always act as the key’s default broker. There is no header for choosing a broker.
403 DEFAULT_BROKER_INACTIVE. We never quietly move a deal to someone else.
Scopes
Give each key only the scopes it needs. A key without the scope an endpoint requires gets403 MISSING_SCOPE.
The portal also offers
applications:read, applications:write, agreements:write, loans:read and webhooks:manage. They’re reserved for endpoints on the roadmap and do nothing yet.
When a request is refused
Turning off your agency’s API access, or revoking a key, stops new API calls straight away. Links to interactive quotes you’ve already sent keep working; see links outlive API access.