Authorization header as a Bearer token. Keys are scoped to projects, so you can manage access and billing separately for each application you build. There are no OAuth flows or session cookies — just a single header on every request.
Getting your API key
Your API key lives in the Noteboxd developer dashboard. To retrieve it:1
Sign in to the developer dashboard
Go to developers.noteboxd.com and sign in with your Noteboxd account.
2
Create or open a project
From the dashboard home, create a new project or click into an existing one. Each project has its own isolated API key and billing balance.
3
Copy your API key
Navigate to the Keys section of the project. Your API key is displayed there — copy it and store it somewhere secure. All keys are prefixed with
nb_live_.Using your API key
Pass your API key in theAuthorization header of every request using the Bearer scheme:
curl example that fetches the full record for a fragrance by its canonical ID:
nb_live_YOUR_KEY with your actual project key. Every endpoint in the Noteboxd API requires this header — requests without it will be rejected with a 401 error.
Security best practices
Store your key in an environment variable and reference it in your code rather than hardcoding it:Auth errors
If something goes wrong with authentication, the API returns a JSON error response with a machine-readablecode field. Here are the auth-related errors you may encounter:
All error responses follow the same shape: