Dumpster Controls · agent page

This is the agent-optimized version of https://dumpstercontrols.io/help/booking-api/lesson-2-keys-domains-and-authentication: the same content as the human page, without scripts, styles, animations or navigation. People should open the full page.

Canonical page
https://dumpstercontrols.io/help/booking-api/lesson-2-keys-domains-and-authentication
Last updated
2026-10-05
Tokens
1,537 tokens (cl100k_base), within the 2,000-token budget for a help page
Size
11 KB for this page, against 23 KB for the human page (53% smaller)
Markdown
https://dumpstercontrols.io/help/booking-api/lesson-2-keys-domains-and-authentication.md, or send Accept: text/markdown to the canonical URL
Cite as
Lesson 2: keys, allowed domains and authentication. Dumpster Controls. https://dumpstercontrols.io/help/booking-api/lesson-2-keys-domains-and-authentication (accessed 2026-10-10).
More for agents
Facts sheet · llms.txt · llms-full.txt · All agent pages · Product manual

Booking API course · updated 2026-10-05

Lesson 2: keys, allowed domains and authentication

Two keys, one rule: the publishable key lives in the browser and only identifies the company; the server key lives in your backend and is never shown again. This lesson covers how to get them, how to send them and why a leaked publishable key cannot hurt you.

Before you start

  • Admin access to Online Booking, Developers
  1. ## Get the publishable key and add your domain
    Open Online Booking, Developers. Under "Open Booking API: your keys" the publishable key (dc_pk_live_...) is already created and shown in full. Under "Allowed domains" add the exact origin of the page that will call the API, for example https://yourcompany.com (https, no path, no wildcard). Browser calls with the publishable key are accepted only from these origins; the app's own origin is always allowed, which is what makes the "Send a test quote" button work.
  2. ## Send the key
    ```
    Authorization: Bearer dc_pk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    ```
    Or, if your HTTP client cannot set Authorization, the header X-DC-Key with the same value. From a browser page the request must carry an Origin header (browsers add it to every fetch); the server checks it against your allowed domains and answers with the matching CORS headers. Preflight (OPTIONS) is always answered with 204 so the browser can continue; the real request is the one that decides.
  3. ## Server key for backend calls
    Calls without an Origin header (a server, a script, a cron) must use a server key: click "Create server key" (dc_sk_booking_...). It is shown once; store it in your backend configuration. Up to two can be active, and you can revoke any of them. A server key used from a browser page is refused with secret_in_browser; a publishable key used without Origin is refused with origin_required.
  4. ## What a leaked publishable key can and cannot do
    It can read what your public booking page already shows (sizes, prices, closed days, company profile), ask for quotes, and start a payment intent that still has to pass every rule and the fraud screening, and that only completes when a real card is confirmed. It cannot change a price, a date, a fee, a promo code, or move money. Browser calls are limited to your domains; payment intents are rate-limited per company and per IP. If you still want a fresh key, click "Rotate": the old one keeps working for 24 hours so your site never breaks.
  5. ## Rate limits
    120 requests per minute per key and 120 per minute per IP before authentication, on every plan. A 429 answer carries Retry-After in seconds. There is no daily window and no per-call fee.

What happens next

  • Test it now: in the Developers tab click "Send a test quote". It calls GET /sizes and POST /quote with your publishable key and shows the JSON.

Troubleshooting

The browser shows a CORS error.

The origin of your page is not in Allowed domains, or you typed it with a path or http. Add the exact https origin and retry. Note that the API returns 403 origin_not_allowed without CORS headers on purpose, which the browser reports as a CORS error.

I get 401 unauthorized from Postman or curl.

Without an Origin header you need a server key (dc_sk_booking_). Or add the header Origin: https://yourcompany.com to simulate the browser with the publishable key.

Related guides

© 2026 Dumpster Controls. All rights reserved. Made in the USA.

Frequently asked questions

Is Dumpster Controls really free?

Yes. The software is free: dispatch, online booking, the driver app, invoicing, the Tresha AI assistant and every other feature, with no monthly fee, no trial period and no credit card to sign up. The only cost on the free plan is optional card processing when a customer pays by card through the platform: 2.99% plus $3.99 per transaction on the free plan. An optional Unlimited plan at $169 per month lowers that to 2.99% plus $0.30. Prices as published on dumpstercontrols.io/pricing on 2026-09-23.

Do you charge per driver, per truck or per order?

No. There is no per-driver, per-truck, per-user or per-order fee, and no order limit. A company with one truck and a company with twenty pay the same for the software: nothing.

Is there a contract?

No. There is no contract, no minimum term and no setup fee. You create the account yourself, and on the free plan there is nothing to cancel because nothing is billed. The optional Unlimited plan is billed month to month.

Which countries and languages are supported?

Dumpster Controls serves hauling companies in the United States and Canada. The app interface and the Tresha AI assistant are available in English, Spanish and Portuguese. The public pages, such as the blog, the help center and the landfill finder, are in English.

How do I switch from another dumpster software?

Create a free account at dumpstercontrols.io/login, with no sales call and no credit card. Then import your customers from a CSV file using the template provided in the app; past orders can also be imported from a CSV. Container sizes and pricing are set up in Settings. The landfill database, with 1,750 active US and Canadian landfills as counted on 2026-10-01, is already loaded, so disposal sites do not need to be typed in. Step-by-step guides are at dumpstercontrols.io/help.