Access Tokens
All API requests must include an access token in the Authorization header using the Bearer scheme.
Getting a Token
- Log into your CostHawk dashboard
- Go to Settings → Developer
- Click Create Token
- Copy the token (displayed only once)
CostHawk tokens are prefixed with ch_sk_ followed by a unique identifier:
Error Responses
401 Unauthorized
No token provided or token is invalid:
403 Forbidden
Token doesn’t have permission for this resource:
Security Best Practices
Never expose your access token in client-side code, public repositories, or logs.
- Store tokens in environment variables
- Use different tokens for dev/staging/production
- Rotate tokens periodically
- Revoke unused tokens immediately