Every API request must prove it comes from your business.
Get a key
- Open the Kilo business dashboard.
- Go to Settings → API & Webhooks.
- Click Create API key.
- Copy the key immediately. We show the full secret only once.
Keys look like sk_live_....
Send the key
Use either header (pick one):
curl -X GET 'https://business.kiloapp.org/api/v1' \ -H 'Authorization: Bearer sk_live_YOUR_SECRET'
curl -X GET 'https://business.kiloapp.org/api/v1' \
-H 'Authorization: Bearer sk_live_YOUR_SECRET'const response = await fetch("https://business.kiloapp.org/api/v1", {
method: "GET",
headers: {
"Authorization": "Bearer sk_live_YOUR_SECRET"
},
});
const data = await response.json();
console.log(data);const response = await fetch("https://business.kiloapp.org/api/v1", {
method: "GET",
headers: {
"Authorization": "Bearer sk_live_YOUR_SECRET"
},
});
const data = await response.json();
console.log(data);import requests
url = "https://business.kiloapp.org/api/v1"
headers = {
"Authorization": "Bearer sk_live_YOUR_SECRET"
}
response = requests.request("GET", url, headers=headers)
print(response.json())import requests
url = "https://business.kiloapp.org/api/v1"
headers = {
"Authorization": "Bearer sk_live_YOUR_SECRET"
}
response = requests.request("GET", url, headers=headers)
print(response.json())<?php
$ch = curl_init("https://business.kiloapp.org/api/v1");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Authorization: Bearer sk_live_YOUR_SECRET",
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;<?php
$ch = curl_init("https://business.kiloapp.org/api/v1");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Authorization: Bearer sk_live_YOUR_SECRET",
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;or:
X-Api-Key: sk_live_YOUR_SECRET
X-Api-Key: sk_live_YOUR_SECRETBase URL
Partner API calls go to the business app host (same Vercel project as the dashboard), not a customer custom domain:
https://business.kiloapp.org/api/v1
https://business.kiloapp.org/api/v1Example create URL:
POST https://business.kiloapp.org/api/v1/deliveries
POST https://business.kiloapp.org/api/v1/deliveriesIf auth fails
| HTTP | Meaning |
|---|---|
| 401 | Missing / wrong / revoked key |
| 403 | Key lacks scope, or billing blocks API access |
| 429 | Plan rate limit — wait, then retry (Retry-After) |
Safety rules for kids (and adults)
- Never paste a live key into Slack, email, or a Discord screenshot.
- Store it in environment variables on your server.
- If it leaks, revoke it in the dashboard and create a new one.
- Respect rate limits. Your plan sets requests per minute per key.