Authentication
Every request except /openapi.json needs an API key, sent in the X-API-Key header or as a bearer token.
Header
GET /companies/10421629 HTTP/1.1
Host: api.regia.ee
X-API-Key: YOUR_API_KEYBearer token
GET /companies/10421629 HTTP/1.1
Host: api.regia.ee
Authorization: Bearer YOUR_API_KEYGetting a key
Keys are issued by Regia: contact us with your company name and expected volume. A key is shown once, so store it in your secret manager. We only keep a hash of it and cannot show it again; a lost key is replaced with a new one.
Keep keys on your server. Anyone holding a key can make billable requests on your account. If a key leaks, ask us to revoke it; a revoked key stops working within a minute.
Failures
A missing key returns 401 api_key_required, an unknown or revoked key 401 invalid_api_key. Each key allows 10 requests per second unless agreed otherwise; beyond that the API answers 429 rate_limited with a Retry-After header.