Skip to content
ReinoAds

Getting startedIntegration Preview

Authentication

Per-environment API keys, secret vs. publishable keys, and webhook signature verification.

Preview

Key prefixes and header names are illustrative. Exact formats are specified in your account-specific integration documentation.

ReinoAds uses a separate key set per environment. Sandbox keys only produce test data; live keys operate on real inventory and revenue. A key from one environment never works in the other.

Key typeExample prefixWhere to use itScope
Secret keysk_sandbox_ / sk_live_Server side onlyManage placements, policies, house ads, webhooks and reports; server-side decision requests
Publishable keypk_sandbox_ / pk_live_Client apps and SDKsDecision requests and event reporting only
Webhook signing secretwhsec_Your webhook receiverVerifying incoming webhook signatures

Never ship secret keys to clients

Secret keys must never be embedded in mobile app bundles, web pages, game clients or public repositories. Use only the publishable key on the client. If you suspect a secret key has leaked, roll it from the dashboard immediately.

Server-side requests

curl https://api.reinoads.com/v1/placements \
  -H "Authorization: Bearer sk_live_..."

Webhook signatures

Every webhook request carries headers with a timestamp and an HMAC-SHA256 signature. The signature is computed with your webhook signing secret over the timestamp joined with the raw request body. To prevent replay attacks, reject any request whose timestamp falls outside your tolerance window.

POST /webhooks/reinoads HTTP/1.1
Content-Type: application/json
ReinoAds-Timestamp: 1767225600
ReinoAds-Signature: v1=5f2b9c0e7a...