The Wave API uses bearer token authentication. Every request must include a valid API key in the Authorization header.
Generate an API key
- Sign in to the Wave Dashboard.
- Navigate to Settings > API Keys.
- Click Create API Key and copy the generated secret. Keys are prefixed with
wave_live_.
API keys grant full access to your Wave account. Store them securely and never commit them to source control.
Authenticate a request
Pass your key in the Authorization header as a bearer token:
Subscription access
Some endpoints require an active Wave subscription. Requests made with a key belonging to an inactive workspace return 403 Forbidden. Upgrade your plan in the Wave Dashboard to unlock access.
Rotate keys
If a key is exposed, revoke it immediately from Settings > API Keys and generate a new one. Old keys stop working the moment they are revoked.