API Authentication

Every request carries an API key in the X-API-Key header. Each key has its own permissions, so every integration can have exactly the access it needs.

Creating an API Key

  1. Sign in to the portal and go to Admin › API Key Management.
  2. Add a key, give it a name you will recognize, and choose its permissions.
  3. Copy the key. It is shown only once, when it is created, so store it in your secrets manager straight away.

Give each integration its own key. You can then revoke or replace one without touching the others.

Sending Your Key

Send the key in the X-API-Key header on every request, over HTTPS, with a JSON content type:

curl -X POST https://www.tincomply.com/api/v1/validate/irs-tin-name-matching \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "tin": "123-12-1234", "name": "JOHN SMITH" }'

Always send Content-Type: application/json (and ideally Accept: application/json). Without one of them the same URL responds with an HTML page instead of JSON.

Permissions

PermissionGrants access to
Validatevalidate and every per-service validation endpoint
Historyhistory and request-details

A key that only submits checks needs Validate. Add History when the same integration reads results back later, for example to pick up a pending result or to reveal an EIN.

Authentication Errors

Every authentication problem returns HTTP 401 with a message that says which one it is:

MessageCause
API key required. Send your key in the X-API-Key header.No key, or an empty one, was sent.
Invalid API KeyThe key is not recognized. It may have been mistyped or revoked.
API key does not have permissions to view this endpointThe key is valid but lacks the permission this endpoint needs.

Other status codes are on the Errors & service status page.