The bluebarry Data API lives at https://data.bluebarry.ai/data. It accepts three kinds of credentials. Which one you need depends on where your code runs and who it acts for.
Choose a method
| Method | How to send it | Use it for |
|---|---|---|
| API key | The raw key in the Authorization header, without a Bearer prefix. | Your own servers and automations. Reads and writes your account's data, for example profiles, products, customers and orders. |
| OAuth token | Authorization: Bearer <token> | Apps that act on behalf of a signed-in bluebarry user, and AI clients connecting to the bluebarry MCP server. |
| Tenant ID | The BB-Tenant-Id header. | Storefront calls only: identify a visitor, and send conversions, page views, product views and cart events. Your Tenant ID is not a secret. |
If a request carries BB-Tenant-Id, bluebarry treats it as a storefront call, even when it also has an Authorization header. Leave that header out of server calls that use an API key or token.
Where to find them

- API keys: Integrations → Developer area → API keys management. See manage API keys.
- Tenant ID: at the top of the Integrations page, with a copy button.
- OAuth: see use OAuth with bluebarry.
- The full endpoint reference is linked as API docs in the Developer area.
Keep credentials safe
- Keep API keys and tokens on your server or in a secret manager. Never put them in storefront JavaScript or a public repository.
- Create one key per integration, so you can remove one without breaking the others.
- Delete keys you no longer use, and replace a key when someone who knew it leaves the project.