Getting startedIntegration Preview
Authentication
Per-environment API keys, secret vs. publishable keys, and webhook signature verification.
Preview
Key prefixes and header names are illustrative. Exact formats are specified in your account-specific integration documentation.
ReinoAds uses a separate key set per environment. Sandbox keys only produce test data; live keys operate on real inventory and revenue. A key from one environment never works in the other.
| Key type | Example prefix | Where to use it | Scope |
|---|---|---|---|
| Secret key | sk_sandbox_ / sk_live_ | Server side only | Manage placements, policies, house ads, webhooks and reports; server-side decision requests |
| Publishable key | pk_sandbox_ / pk_live_ | Client apps and SDKs | Decision requests and event reporting only |
| Webhook signing secret | whsec_ | Your webhook receiver | Verifying incoming webhook signatures |
Never ship secret keys to clients
Secret keys must never be embedded in mobile app bundles, web pages, game clients or public repositories. Use only the publishable key on the client. If you suspect a secret key has leaked, roll it from the dashboard immediately.
Server-side requests
curl https://api.reinoads.com/v1/placements \
-H "Authorization: Bearer sk_live_..."Webhook signatures
Every webhook request carries headers with a timestamp and an HMAC-SHA256 signature. The signature is computed with your webhook signing secret over the timestamp joined with the raw request body. To prevent replay attacks, reject any request whose timestamp falls outside your tolerance window.
POST /webhooks/reinoads HTTP/1.1
Content-Type: application/json
ReinoAds-Timestamp: 1767225600
ReinoAds-Signature: v1=5f2b9c0e7a...