Pairing & security
How a device joins your account, the safeguards on pairing codes and device keys, and what to do if one is exposed.
- Pairing code
- 6 digits, single use
- Code lifetime
- 10 minutes
- Wrong-code limit
- 10 per 15 minutes, per IP
Pairing codes
When you add a device, the dashboard creates a 6-digit code. You enter it on the device's own page, and the device redeems it with the API. The code is the only thing that links a device to your account, so it is deliberately short-lived.
429. The proxy also limits pairing requests to 10 a minute per IP.Device keys
Redeeming a code gives the device its own API key, which it sends with every upload to POST /records.
401.Pairing step by step
- 1Dashboard
Add device. The dashboard shows a code and a 10-minute countdown.
POST /pairing/codes - 2Device page
Enter the code. The device sends it with its hardware ID and receives its key.
POST /pairing/redeem - 3Dashboard
Check the hardware ID. The dashboard shows which device redeemed the code. Make sure it matches the ID on the device's page.
GET /pairing/codes/{code} - 4Dashboard
Confirm. Name the device and choose its bin. Until you do, its uploads are answered with
409.POST /devices/{id}/setup
If the hardware ID in step 3 isn't yours, don't confirm it. Remove the device and create a new code. An unconfirmed device can't add readings to your account.
If a code or key is exposed
| What was exposed | What to do |
|---|---|
| A pairing code nobody has used | Nothing. Let it expire, or create a new one. |
| A pairing code someone else redeemed | Don't confirm the unknown hardware ID. Remove it and create a new code. |
| A device key | Unpair the device in the dashboard, then pair it again to get a new key. |
| Your password | Change it on the account page. Sessions that are already signed in end within 8 hours. |
Accounts and sessions
401 response./auth/, then 429.404.What the open data includes
Readings shared through the open data API are anonymised first: no names, emails, bin names, locations finer than country, or device identifiers. The data dictionary lists every field.
Reporting a vulnerability
Email [SECURITY CONTACT EMAIL] with the steps to reproduce it. Please don't disclose it publicly until it has been fixed.