Skip to content

Authentication

Partner API requests must include an Orbit-issued token.

Preferred header:

http
Authorization: Bearer orb_ext_your_token

Fallback header:

http
X-Orbit-API-Token: orb_ext_your_token

Token Handling

Tokens are generated by Orbit, stored hashed, and can be revoked or regenerated by Orbit staff.

For partner systems:

  • Store tokens only in backend secrets.
  • Do not hard-code tokens into public repositories.
  • Rotate a token immediately if it may have been exposed.
  • Keep request logs from recording full token values.

Rate Limits

Current limits include:

ScopeLimit
Authenticated token30/sec
Player status per token and UUID10/sec and 300/min

If you receive 429 Too Many Requests, slow down and retry later.

Errors

StatusMeaning
401Missing, invalid, or revoked token.
429Rate limit exceeded.
503Presence backend unavailable.

Orbit Client API Documentation