Send the Bearer token
Every API request should include the API token in the Authorization header.
Authorization: Bearer adk_live_<keyId>_<secret>
Tokens are shown once when created. Store the full token in your secret manager; it cannot be recovered later.
Create, rotate, and revoke keys
- Create API keys from the Alva API keys settings page after your shop is approved.
- Rotate credentials by creating a new key, updating your integration, then revoking the old key.
- A missing, malformed, unknown, or revoked key returns the same unauthorized response.
- Never send shop ids in request bodies to select a shop. The API scopes access from the token.
API docs
Was this helpful?
Last updated 2026-06-05