Skip to main content
Nexenergie uses Bearer token authentication for all API requests. Every call you make must include an Authorization: Bearer <token> header — requests without a valid credential are rejected before they reach any forecast data. You can authenticate with either a short-lived session token obtained by exchanging your username and password, or a long-lived API key generated from the dashboard.

Obtaining a Token

Exchange your Nexenergie username (email address) and password for an access token by calling POST /auth/token. The request body must be sent as application/x-www-form-urlencoded.
A successful response returns HTTP 200 with the following JSON body:
Response
string
The Bearer token to include in the Authorization header of every subsequent API request.
string
Always "bearer".
integer
Number of seconds until the token expires. Session tokens are valid for 86 400 seconds (24 hours).

Using Your Token

Pass the token in the Authorization header as Bearer <token> on every request to the Nexenergie API.

API Keys

For production applications and automated pipelines, use a long-lived API key instead of a session token. API keys do not expire automatically and are easier to rotate on a schedule you control. To generate an API key:
  1. Log in to the Nexenergie dashboard.
  2. Navigate to Account → API Keys (or go to app.nexenergie.ai/account/api-keys).
  3. Click Generate New Key, enter a descriptive label, and click Create.
  4. Copy the key immediately — it is displayed in full only once.
Use an API key exactly like a session token: pass it in the Authorization: Bearer <api-key> header. There is no difference in the request format between the two credential types.
Never commit tokens or API keys to source control, share them in Slack or email, or include them in client-side code that is shipped to end users. If a credential is compromised, revoke it immediately from Account → API Keys in the dashboard and generate a replacement.

Token Expiry

Session tokens obtained via POST /auth/token expire after 24 hours (expires_in: 86400). After expiry, any request using that token returns 401 Unauthorized. Re-authenticate by calling POST /auth/token again with your credentials to obtain a fresh token.
Store the expires_in value alongside your token and proactively refresh it a few minutes before expiry to avoid failed requests during active sessions.
Long-lived API keys do not have an automatic expiry. You can revoke and replace them at any time from the dashboard.

Authentication Errors

The table below lists the HTTP error codes you may receive when authentication fails.