Skip to main content

EDI API authentication

How SignalEDI platform API keys work: Bearer auth, platform vs workspace scopes, rotation, and rate-limit headers.

Bearer token pattern

Every /api/v1 request carries Authorization: Bearer <SIGNALEDI_API_KEY>. Missing or invalid keys return 401 without leaking tenant details.

Authorization: Bearer $SIGNALEDI_API_KEY

Scopes

Platform-scoped keys power developer integrations (/api/v1/*). Workspace-scoped keys remain tied to SMB dashboard flows.

  • Platform scope → developer console + /api/v1
  • Workspace scope → tenant dashboard APIs

Rate limits

Responses include X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset. Back off with jitter when you receive 429.

Common questions

Built for SMB teams that need API-first EDI, healthcare diligence, and predictable pricing.

SignalEDI keeps the public promise consistent across every route: real-time processing, transparent monthly plans, no per-document fees, QuickBooks-friendly handoffs, and core healthcare X12 workflows on paid plans.

HIPAA-aware handlingBAA path documentedSecure API + webhooksNo per-document fees

Operations teams

A supplier operations team can see partner setup, validation, exceptions, and QuickBooks handoff in one workspace instead of chasing spreadsheets.

Healthcare billing

837, 835, and 270/271 workflows are explained in plain English, with HIPAA-aware handling and a documented BAA review path for diligence.

Developer teams

JSON/CSV in and X12 out, with API docs, webhooks, real-time status, and validation responses that make EDI feel like modern infrastructure.

Preview case studies

© 2026 CCCM Consulting LLC. All rights reserved.