Billing and access for APIs

Add API keys, rate limits and billing to your API

MicroAuth gives you a branded developer portal and an SDK for your backend. Developers sign up, create keys and pay, while your API checks every request itself. Your traffic never goes through MicroAuth.

No gateway, no proxy and no cut of your revenue. Moving off Kong?

from fastapi import FastAPI, Security
from microauth_fastapi import MicroAuth, Customer

app = FastAPI()
auth = MicroAuth(app)  # reads MICROAUTH_SECRET_KEY

@app.get("/forecast")
async def forecast(customer: Customer = Security(auth)):
    return {"hello": customer.id}
Keys, rate limits, quotas and billing on every route that asks for a customer.

How it works

From API to paid product in three steps

Step 1

Launch a developer portal

Name your API, pick how developers pay and your portal is live at yourapi.microauth.dev. Developers sign up there, create keys, see their usage and pay. Add your logo, colors and your own domain whenever you like.

Step 2

Protect and meter your API

Add the SDK to check keys, enforce each customer's limits and count usage inside your service. It works from a cached copy, so MicroAuth stays out of your request path.

FastAPI has a ready made SDK. Any other stack can call the same three HTTP endpoints.

Terminal
  • $ curl https://api.weather.example/forecast

    401{"detail":"Invalid or missing API key"}

  • $ curl https://api.weather.example/forecast -H "X-API-Key: map_…"

    200{"forecast":"sunny","high":24}

  • # the same key, over its rate limit

    429{"detail":"Rate limit exceeded"}

  • # a customer with no credit left

    402{"detail":"Insufficient credit balance"}

Step 3

Let developers sign up and pay

Developers top up credit or subscribe to a plan on your portal, and the money goes straight to your Stripe account. You see usage, balances and earnings without building an account or billing system yourself.

On every request

Request checks stay inside your API

  1. Key checked

    The SDK looks the key up in its local copy. No call to MicroAuth.

  2. Limits enforced

    Rate limits, quotas and balance rules run in your process.

  3. Response returned

    Your handler runs without a round trip anywhere else.

  4. Usage reported

    Counts go to MicroAuth in the background, batched and idempotent.

If MicroAuth is ever unreachable, your API keeps serving known keys from its cached copy and sends the buffered usage once the connection is back.

Features

Everything you need to run a paid API

A branded developer portal

Developers sign up, create keys, see usage and pay in one place, on a MicroAuth address or your own domain.

Managed API keys

Developers create and revoke their own keys. Your API checks them against a local copy, so a key check never waits on the network.

Rate limits and quotas

Set limits for everyone, per plan or for one customer. The SDK enforces them in your API, and Redis shares them across workers.

Usage based billing

Charge per request from prepaid credit, sell monthly plans, or both. You decide which response codes cost money.

Paid through your own Stripe

Connect Stripe in one click. Top ups, subscriptions and automatic top ups pay you directly. Bill another way? Add credit through the API.

Teams and security

An activity log you can export and two step verification on every plan. On Scale, you and your customers can invite teammates with roles.

Flat monthly pricing. No revenue share.

Start free with 1M requests a month. Your developers pay you directly through your own Stripe account, and we never touch that money.

See pricing

Questions

What developers ask us

Does my API traffic go through MicroAuth?

No. MicroAuth isn't a gateway or a proxy. The SDK inside your API caches customer limits and reports usage counts in batches. Request bodies, headers, query parameters and responses never leave your servers.

What happens to my API if MicroAuth goes down?

Your API keeps serving. The SDK works from its cached copy and holds usage reports until MicroAuth is reachable again. You choose the behavior: keep serving known keys, or refuse requests once the cached data is older than a limit you set.

How do my customers pay me?

They top up credit or subscribe to your plans with Stripe Checkout on your portal, and the money lands in your own Stripe account. If you bill another way, add credit from your own system with one API call.

Do you take a cut of my revenue?

No. Payments go straight to your Stripe account. You pay a flat monthly price per API and nothing per transaction.

I don't use Python. Can I still use MicroAuth?

Yes. FastAPI has a ready made SDK, and any other language can call the same three HTTP endpoints the SDK uses. See the HTTP guide.

We run Kong today. How hard is it to switch?

You can run both side by side while you move. Consumers become customers, key-auth credentials become keys your customers create on your portal, and rate limits move into plans or per customer limits that the SDK enforces. Once traffic has moved over, the gateway can go. Read the migration guide.

Turn your API into a paid product today

Launch it in the dashboard, add two lines to your code and share your portal link. Your first paying customer is one sign up away.