The API surface available today
ReplayCore has four authentication surfaces, each scoped to one tenant:
1. Customer API keys (the developer API). Mint an rc_live_ bearer key under Settings, then Developer API, grant it scopes (such as replays:write), and call the programmatic endpoints under /v1/api. This is the supported way to integrate your own plugin or tooling. See the API keys article.
2. The panel itself. Everything you do in the dashboard (replays, servers, licences, billing, team, settings) goes through authenticated panel routes using your signed-in session. This is the supported way to manage your account.
3. The plugin protocol at api.replaycore.com/v1. These endpoints are authenticated with ReplayCore request signing using your tenant's licence-derived signing credentials. They exist for the recorder plugin, and integrators can call the documented ones (for example the replay-categories read used to drive recordings).
4. Public share links. A minted share link token is itself the credential for watching that one replay in the browser; no account is needed.
Do not embed your panel session cookie in scripts; use a customer API key for automation instead.
ReplayCore request signing (v1 endpoints)
Every authenticated /v1 request carries an Authorization header in the ReplayCore scheme. The signature is computed over the request using your tenant's signing secret, with a timestamp and nonce to prevent replay:
Authorization: ReplayCore tenant=<tenant-id>, ts=<unix-ms>, nonce=<nonce>, sig=<hex>, kid=<key-id>Unauthenticated endpoints
POST /v1/handshake (licence validation, authenticated by the licence key in the body), POST /v1/license/verify, and GET /health carry no Authorization header. Everything else under /v1 requires a valid request signature and is scoped to the signing tenant.
Response format
All API responses use JSON. Successful responses return the requested resource. Errors return a status, a machine-readable code, and a human-readable detail:
{
"status": 401,
"code": "MISSING_TENANT",
"detail": "missing authenticated tenant context"
}Rate limits
Requests are rate-limited per tenant. A request over the limit returns HTTP 429; back off and retry. Limits are sized so normal recorder and panel traffic never hits them.