A

AfriRoute

Developer Portal

public api
Sign in
Authentication

Use external API keys for public developer integrations

AfriRoute’s public developer surface leads with API-key access in the Authorization header. Account login, refresh, and console session APIs are internal application concerns and should not be published as public API reference entries.

Recommended flow

Use sandbox or production external API keys for first-run testing and place the key in the Authorization header for messaging, verification, webhooks, and other public integration flows.

Keep account login, refresh, and console session mechanics inside the application boundary. The public portal should describe how developers authenticate external API requests, not expose internal session endpoints.

What to surface

Authorization: Bearer YOUR_EXTERNAL_API_KEY
Sandbox and production keys stay separate
Scopes describe public product access
Never place API keys in browser-only code
Rotate keys from the authenticated console