Authentication
Bearer tokens for the official API and session cookies for the internal routes.
The two APIs authenticate differently.
Official API
Official operations take a bearer token issued from the BUFF developer console.
Authorization: Bearer <token>Access is tiered. Each operation states whether it needs Developer or Enterprise access, along with its update frequency and request limit.
Internal API
Internal operations have no documented credential. Some answer anonymous requests; others require
the cookies of a signed-in BUFF session, sent in the Cookie header.
Cookie: session=<redacted>Keep those cookies server-side. A route that rejects an anonymous request returns an
application-level Login Required in msg rather than an HTTP 401.