Skip to content

GET /api/v1/votes/claim is removed on October 1, 2026.

See the migration

Authentication

Bearer, uniform 401, 403 sanctioned owner, rate limits, deprecated query token.

Every Hub /api/v1/* call requires:

Authorization: Bearer <your token>

Generate the token in Manage → Settings. It is shown once. Regenerating invalidates the old one.

Uniform 401

Missing, malformed, unknown or invalid token: always 401 { "error": "invalid_token" }.

Owner 403

If the server owner is sanctioned from publishing: 403 { "error": "owner_sanctioned" }. The token is valid; the account is blocked.

Rate limits

Calls are limited per connection, then per authenticated route:

RouteCap / min
all (per connection)240
check60
claim30
ranking120

Over the cap: 429 with Retry-After (seconds).

Deprecated query string

?server_token= is still accepted for legacy scripts — stop using it: a secret in the URL leaks. Put the token in Authorization. Cut-off: 2026-10-01.