Skip to main content

User API keys

API keys are credentials used to authenticate requests. The authentication scheme and required headers are specified per operation.

For operations that use a project or user API key, send it in the X-Api-Key header:

X-Api-Key: YOUR_API_KEY

YOUR_API_KEY is a placeholder. Never place a real key in documentation, screenshots, browser code, mobile bundles, source control, URLs, analytics, or chat.

Security practices​

  • Keep keys in a server-side secret manager or protected environment variable.
  • Use credentials only for the user and access level required by the integration.
  • Do not share one key across unrelated environments or services.
  • If an authorized key-management flow is available to your project, rotate a key by creating a replacement, updating and verifying the server-side consumer, then revoking the old key.
  • Treat a leaked key as compromised and revoke it through an authorized workflow.

The current API reference does not document user-key management operations.