Authentication

Bearer tokens for the official API and session cookies for the internal routes.

The two APIs authenticate differently.

Official API

Official operations take a bearer token issued from the BUFF developer console.

Authorization: Bearer <token>

Access is tiered. Each operation states whether it needs Developer or Enterprise access, along with its update frequency and request limit.

Internal API

Internal operations have no documented credential. Some answer anonymous requests; others require the cookies of a signed-in BUFF session, sent in the Cookie header.

Cookie: session=<redacted>

Keep those cookies server-side. A route that rejects an anonymous request returns an application-level Login Required in msg rather than an HTTP 401.

On this page