bluebarry.
ReviewsPricingResources
Sign inBook demoBook a 15 min demo
Help Center/Developer platform/API authentication overview

API authentication overview

Martijn Douma
Martijn Douma · Co-founder bluebarry
Updated September 25, 2026

The bluebarry Data API lives at https://data.bluebarry.ai/data. It accepts three kinds of credentials. Which one you need depends on where your code runs and who it acts for.

Choose a method

Authentication methods
MethodHow to send itUse it for
API keyThe raw key in the Authorization header, without a Bearer prefix.Your own servers and automations. Reads and writes your account's data, for example profiles, products, customers and orders.
OAuth tokenAuthorization: Bearer <token>Apps that act on behalf of a signed-in bluebarry user, and AI clients connecting to the bluebarry MCP server.
Tenant IDThe BB-Tenant-Id header.Storefront calls only: identify a visitor, and send conversions, page views, product views and cart events. Your Tenant ID is not a secret.

If a request carries BB-Tenant-Id, bluebarry treats it as a storefront call, even when it also has an Authorization header. Leave that header out of server calls that use an API key or token.

Where to find them

The Developer area on the Integrations page with the API keys and Webhooks cards.
  • API keys: Integrations → Developer area → API keys management. See manage API keys.
  • Tenant ID: at the top of the Integrations page, with a copy button.
  • OAuth: see use OAuth with bluebarry.
  • The full endpoint reference is linked as API docs in the Developer area.

Keep credentials safe

  • Keep API keys and tokens on your server or in a secret manager. Never put them in storefront JavaScript or a public repository.
  • Create one key per integration, so you can remove one without breaking the others.
  • Delete keys you no longer use, and replace a key when someone who knew it leaves the project.

Related articles

Manage API keys

Create an API key in the Developer area on the Integrations page, send it with your requests, and replace or delete keys you no longer need.

Read article →

Use OAuth with bluebarry

The bluebarry OAuth endpoints, scopes and flow for AI clients using the MCP server and for partner apps that act on behalf of bluebarry users.

Read article →

Use the Identify API

Attach an email to a visitor with window.barry.identify or POST /data/identify, so their earlier visits join their customer profile.

Read article →

Can’t figure it out? We probably can.

Every article here was written by the people who built the product. If one of them still leaves you stuck, tell us and we’ll fix it.

Contact usJoin Discord, free forever
bluebarry.

Helping beauty, health and outdoor brands reach their dream AOV

[email protected]+31 6 57 16 10 87De Ried 10, 9285KK Buitenpost (The Netherlands)
Martijn DoumaStan van RooyAnco PostmaJelmer Reitsma

The guys that are increasing your AOV.

Platform
Quiz funnelsLanding pagesProduct QuizRecommendationsSearchIntegrationsPricing
Resources
CasesHelp centerFAQCompare
Company
Contact usPartners & affiliateReviewsRequest demo
Book a 15 min demo
© 2026 bluebarry. All rights reserved.
Privacy PolicyCookie PolicyTerms & Conditions
English/Nederlands/Deutsch
bluebarry