Metrc API Keys: How Authentication Works
Before you can pull a single package out of Metrc programmatically, you have to authenticate. This guide explains how keys work on Metrc’s own API, where that model creates friction for in-house teams, and how the T3 API handles authentication with one secret key and no Metrc API key at all.
Updated
The two keys behind a Metrc API request
Metrc’s official API is designed for third-party software integrators. Each request carries two credentials that answer two different questions: which software is calling, and which Metrc user it is acting for.
The vendor (integrator) API key
The vendor key, sometimes called the software or integrator key, identifies the application making the request. Metrc issues it to a software company that has gone through its integrator onboarding, and access is generally arranged state by state. In-house development teams often discover this requirement only after they have started planning an integration.
The user API key
The user key identifies the person the software acts for. A licensed Metrc user generates it from inside their Metrc account, and requests made with it are limited to the facilities and permissions that user already has. If that user’s access changes, or they leave the company, the key has to be replaced.
How the keys travel with each request
Both keys are sent with every request, typically as HTTP Basic authentication: the vendor key in the username position and the user key in the password position. Each Metrc state also runs its own API host, so a multi-state integration maintains separate configuration for every state it touches.
Where the key model creates friction
None of this is unusual for a regulated system, but it adds overhead before an in-house team ships anything useful:
- Access depends on approval. Without a vendor key there is no Metrc API access, no matter how many licenses the company holds.
- Keys multiply. Every state and every user who needs automated access adds credentials to issue, store, and rotate.
- Behavior varies by state. Metrc behaves differently in each state it operates in, so an integration built for one state may need changes before it works in another.
Authenticating to the T3 API
The T3 API takes a different approach. It does not use Metrc API keys and is not built on Metrc’s third-party API. Instead, the developer-friendly T3 API reaches the same data you can already see on metrc.com using your own Metrc login, and it accepts two authentication formats. Every endpoint that requires authentication accepts either one.
Option 1: A single T3 secret key
Generate a secret key once by sending your Metrc username, password, and hostname (the site you log in to, such as ca.metrc.com) to POST /v2/auth/secretkey, or use the secret key generation tool. Colorado users also supply their Metrc email, and Michigan users supply their one-time password seed. After that, every request carries the key:
curl "https://api.trackandtrace.tools/v2/packages/active?licenseNumber=LIC-000123" \
-H "X-T3-API-Key: $T3_API_KEY"The X-T3-API-Key header is the preferred form. The same key can be passed as a secretKey query parameter, which is what makes spreadsheet formulas possible, but query strings tend to end up in logs and browser history. When both are present, the header wins.
Option 2: Credential authentication with a bearer token
For interactive work, exchange your Metrc credentials at POST /v2/auth/credentials for a short-lived JWT, then send it as Authorization: Bearer <jwt>. Your credentials are used once to log in to Metrc and are not stored. When the token expires, you authenticate again.
import requests
auth = requests.post(
"https://api.trackandtrace.tools/v2/auth/credentials",
json={
"hostname": "ca.metrc.com",
"username": "your-metrc-username",
"password": "your-metrc-password",
},
timeout=60,
)
auth.raise_for_status()
token = auth.json()["accessToken"]
licenses = requests.get(
"https://api.trackandtrace.tools/v2/licenses",
headers={"Authorization": f"Bearer {token}"},
timeout=60,
)
print(licenses.json()) # [{"licenseName": "...", "licenseNumber": "..."}]Choosing between them
| Secret key | Bearer JWT | |
|---|---|---|
| Best for | Scheduled jobs, server-to-server integrations, Spreadsheet Sync | Interactive scripts, notebooks, Postman or curl exploration |
| What you send | X-T3-API-Key header or secretKey param | Authorization: Bearer <jwt> |
| Lifetime | Until you delete it or your Metrc credentials change | Short-lived; repeat the exchange when it expires |
| Credential storage | Encrypted at rest so T3 can re-authenticate with Metrc for you | Not stored; used once per login |
Keeping a secret key healthy
- Regenerate after credential changes. A secret key embeds a snapshot of the credentials used to create it. If your Metrc password, username, Colorado email, or Michigan OTP seed changes, the key stops working and must be replaced.
- Audit and revoke.
GET /v2/auth/secretkeylists your active keys along with theirlastUsedAtactivity, andDELETE /v2/auth/secretkey/{id}revokes one immediately, with no grace period. - Treat it like a password. Keep it in an environment variable or secrets manager, never in source control or a shared spreadsheet.
- Stay inside rate limits. The default limit is 600 requests per minute per user, and some routes are lower. A key shares one rate-limit bucket whether you send it as a header or a query parameter.
Metrc API keys vs. the T3 API at a glance
| Metrc API | T3 API | |
|---|---|---|
| Credentials | Vendor API key plus user API key | One T3 secret key, or a bearer JWT from your Metrc login |
| Who can get access | Software companies approved as integrators | Any Metrc user; most endpoints require T3+ |
| Multiple states | Separate configuration per state | One consistent interface for every Metrc state |
What access costs
Next steps
With a secret key in hand, the fastest way to see results is to make a real request. The Python guide walks through fetching and paginating active packages, and the documentation map shows what else you can reach. For a broader look at what teams build, see the T3 API feature overview, or read the full authentication reference on the T3 wiki.
Related guides
Using the Metrc API with Python
Put a secret key to work: fetch packages with requests and paginate full collections.
Metrc API documentation map
Every domain the API covers, from packages and plants to transfers and reports.
How to export Metrc data
Use a secret key to pull full datasets into CSV, Excel, or Google Sheets.
What is Metrc?
A plain-language primer on seed-to-sale tracking for cannabis operators.
The best way to talk to Metrc
The T3 API gives developers one consistent REST interface to Metrc data across every Metrc state, with interactive OpenAPI documentation, predictable JSON, and reports that export full datasets in a single request.
Track & Trace Tools is not affiliated with Metrc.