Docs / Getting started

Authentication

API keys, the Authorization header, and what a key can do.

Reading the catalog needs no key. A key gets you photos, contributing, and a higher rate limit:

GET /v1/items?q=catan
Authorization: Bearer bgdb_…
Without a keyWith a key
Items, search, lookup, credits, terms, historyyesyes
Photo linksfirst page of a list onlyyes
Submissions and uploadsnoyes
Requests per minute120 per address600 (user) or 6,000 (bot)

Keys

Make keys in the web app under Account → API keys. Each key is shown once, has a label so you know what it is for, and can be revoked there. A key never expires on its own.

Treat a key like a password: keep it in an environment variable or a secret store, not in client-side code. If a key leaks, revoke it and make another.

What a key can do

With a key you canNot with a key
Read everythingCreate accounts, log in, or reset passwords
Submit new items and changes (see Submissions)Review or approve anything
Upload photosMake or revoke keys
See your own submissions and GET /v1/meAdmin functions

Accounts and administration happen only in the web app. An admin's API key acts like any user's key: its submissions wait for review.

Roles

RoleSubmissionsRate limit
userReviewed by an admin before publishing600 requests/minute
botPublished at once, unless flagged as a possible duplicate6,000 requests/minute

Bot keys are given to scrapers and trusted integrations. Ask if you need one.