API

API keys

Create, list and revoke a club API key, then send it with each request.

Keys belong to a club, not to a person. A key can read that club and nothing else. Club owners and admins manage keys, and any club can create them.

Create a key

  1. Open the Superstat app and go to Settings.
  2. In API keys, enter a name that says where the key will be used, for example Club website.
  3. Choose Create key.
  4. Copy the secret. It starts with ss_live_ and is shown only once.

The list in Settings keeps the name and a short prefix such as ss_live_a1b2c3d4 so you can tell keys apart. It never shows the full secret again. A club can have up to 20 active keys.

Send the key

Pass the secret as a bearer token on every request:

curl https://api.superstatsport.com/v1/clubs \  -H "Authorization: Bearer ss_live_your_secret"

An X-Api-Key: ss_live_your_secret header is accepted as well.

Keep the key on a server. Do not ship it in a mobile app or in browser code, where anyone could read it.

Revoke a key

In Settings → API keys, choose Revoke next to the key. Requests that still use it fail with 401 straight away. Revoked keys stay in the list with the date they were turned off.

Try it

Every page in the API reference has a Test button that sends a request from your browser. Paste a key into the authorization field to use it.

On this page