Authentication

Every request except /openapi.json needs an API key, sent in the X-API-Key header or as a bearer token.

Header
GET /companies/10421629 HTTP/1.1
Host: api.regia.ee
X-API-Key: YOUR_API_KEY
Bearer token
GET /companies/10421629 HTTP/1.1
Host: api.regia.ee
Authorization: Bearer YOUR_API_KEY

Getting a key

Keys are issued by Regia: contact us with your company name and expected volume. A key is shown once, so store it in your secret manager. We only keep a hash of it and cannot show it again; a lost key is replaced with a new one.

Keep keys on your server. Anyone holding a key can make billable requests on your account. If a key leaks, ask us to revoke it; a revoked key stops working within a minute.

Failures

A missing key returns 401 api_key_required, an unknown or revoked key 401 invalid_api_key. Each key allows 10 requests per second unless agreed otherwise; beyond that the API answers 429 rate_limited with a Retry-After header.

Cookies

We use the cookies the portal needs to work and, with your consent, Google Analytics to understand how the portal is used. Learn more