Skip to main content
Every request carries an API key in the Authorization header:
There’s no other credential, no OAuth flow and no request signing. Keep keys on your server; never put one in a browser, a mobile app or a URL.

Keys and modes

A key’s prefix tells you its mode: The rest of the key is 43 random characters and a 6-character checksum, so secret scanners (GitHub’s included) can recognize a leaked key. We store only a SHA-256 hash: a lost key can’t be recovered, so revoke it and create a new one.

Getting a key

  1. Bridgeline turns on API access for your agency. During the beta this is by invitation; ask your Bridgeline contact. Live keys and test keys are enabled separately: ask your Bridgeline contact to enable test mode if you want test keys.
  2. An agency admin opens API Keys in the Bridgeline portal and creates a key: its mode (live or test), name, type, default broker, scopes and an optional expiry date.
  3. The full key is shown once. Copy it into your secret manager.
The portal shows each key’s last-used time. An integration can hold two active keys at once, so you can rotate without downtime: create the new key, deploy it, then revoke the old one.

Key types

Every request acts as one of your agency’s active brokers, so every quote has a named owner in Bridgeline, just as it does in the portal.

Acting as a broker

Write requests that create something take an optional broker_email in the JSON body. Today that’s POST /v1/quotes:
  • Agency key: any active broker at your agency. Leave it out and the request acts as the key’s default broker. Set it from the logged-in user in your system, so each quote lands with the right producer.
  • Broker key: leave it out, or send the key’s own broker. Naming anyone else returns 403 ACTING_BROKER_NOT_ALLOWED.
  • An email that isn’t an active broker at your agency returns 403 BROKER_NOT_ACTIVE. We give the same answer whether the person is inactive or works somewhere else.
  • Reads, and requests with no body, always act as the key’s default broker. There is no header for choosing a broker.
If the key’s default broker is deactivated, requests that rely on the default fail with 403 DEFAULT_BROKER_INACTIVE. We never quietly move a deal to someone else.

Scopes

Give each key only the scopes it needs. A key without the scope an endpoint requires gets 403 MISSING_SCOPE. The portal also offers applications:read, applications:write, agreements:write, loans:read and webhooks:manage. They’re reserved for endpoints on the roadmap and do nothing yet.

When a request is refused

Turning off your agency’s API access, or revoking a key, stops new API calls straight away. Links to interactive quotes you’ve already sent keep working; see links outlive API access.