Scroll top

Examples

Custom icon

An API key belongs to one organisation and carries scopes: send, read logs, or manage connections.

A key is shown once, when it is created. Store it in your secrets manager, never in the code.

Rotate a key by creating a new one, moving your sites to it, then revoking the old one.

A revoked key stops working at once. Requests with it get a 401 reply and are logged.

Keys that have not been used for 90 days are flagged on the API keys page.

Every request names its key in the audit log, with the address it came from.