API Authentication
The Galaxy Nexus API supports two authentication methods: API Keys and OAuth2.
API Keys
Generating an API Key
- Navigate to Dashboard → Settings → API
- Click Generate New Key
- Copy and securely store your key
Security
API keys are only shown once at creation time. Store them securely and never expose them in client-side code.
Using API Keys
Include your API key in the Authorization header:
curl -X GET https://api.galaxynexus.au/v1/servers \
-H "Authorization: Bearer gnx_live_xxxxxxxxxxxxx"Key Types
| Type | Prefix | Permissions |
|---|---|---|
| Live | gnx_live_ | Full access |
| Test | gnx_test_ | Full access (no charges) |
OAuth2
For applications that need to act on behalf of users, use OAuth2.
Authorization Flow
# Step 1: Redirect user to authorize
GET https://galaxynexus.au/oauth/authorize?
client_id=YOUR_CLIENT_ID&
redirect_uri=https://your-app.com/callback&
response_type=code&
scope=read+write
# Step 2: Exchange code for token
POST https://api.galaxynexus.au/oauth/token
Content-Type: application/x-www-form-urlencoded
grant_type=authorization_code&
code=AUTH_CODE&
client_id=YOUR_CLIENT_ID&
client_secret=YOUR_CLIENT_SECRET&
redirect_uri=https://your-app.com/callback
# Step 3: Use the access token
GET https://api.galaxynexus.au/v1/user
Authorization: Bearer ACCESS_TOKENAvailable Scopes
| Scope | Description |
|---|---|
read | Read access to resources |
write | Create and modify resources |
servers | Full server management |
bots | Full bot management |
billing | Billing and payments |
Token Refresh
Access tokens expire after 1 hour. Use the refresh token to obtain a new access token:
POST https://api.galaxynexus.au/oauth/token
Content-Type: application/x-www-form-urlencoded
grant_type=refresh_token&
refresh_token=REFRESH_TOKEN&
client_id=YOUR_CLIENT_ID&
client_secret=YOUR_CLIENT_SECRETError Codes
| Code | Description |
|---|---|
INVALID_TOKEN | The provided token is invalid or expired |
INSUFFICIENT_PERMISSIONS | Token lacks required scope |
RATE_LIMITED | Too many requests |