User API keys
API keys are credentials used to authenticate requests. The authentication scheme and required headers are specified per operation.
For operations that use a project or user API key, send it in the X-Api-Key header:
X-Api-Key: YOUR_API_KEY
YOUR_API_KEY is a placeholder.
Never place a real key in documentation, screenshots, browser code, mobile bundles, source control, URLs, analytics, or chat.
Security practices
- Keep keys in a server-side secret manager or protected environment variable.
- Use credentials only for the user and access level required by the integration.
- Do not share one key across unrelated environments or services.
- If an authorized key-management flow is available to your project, rotate a key by creating a replacement, updating and verifying the server-side consumer, then revoking the old key.
- Treat a leaked key as compromised and revoke it through an authorized workflow.
The current API reference does not document user-key management operations.