API keys and key security
Creating, storing, rotating and revoking API keys — and exactly what to do if one leaks.
- Last updated
- Updated
- Reading time
- 1 min read
API keys authenticate requests to the REST API. A key acts for your account — it can spend your balance — so treat it like a password.
Format
Keys start with pc_live_ followed by 32 letters and digits. Send yours in the Authorization header:
Authorization: Bearer pc_live_…In the dashboard we only ever show a key's first characters (for example pc_live_a1B2), so you can tell keys apart without exposing them.
Creating keys
Create keys on the API keys page, and give each a name that says where it's used: "production server", "staging", "price monitor". The full key is shown once, when you create it. We store only a one-way hash, so we can't show it again or recover it. Lost a key? Create a new one and revoke the old.
You can have up to 20 active keys.
Keeping keys safe
- Keep keys on your server. Never ship them in a mobile app, in browser JavaScript, or in a public repository.
- Load them from environment variables or a secrets manager, not from source code.
- Use a separate key per environment or service, so you can revoke one without breaking the rest.
- Keep an eye on last used on the API keys page. A key being used when you don't expect it is a reason to revoke it.
Rotating a key
- Create a new key.
- Deploy it everywhere the old one is used.
- Check that the old key's last-used time has stopped moving.
- Revoke the old key.
If a key leaks
Warning
Revoke it immediately on the API keys page. Revocation takes effect on the very next request: anything still using the key is rejected as unauthorized.
Then review your ledger and order history for activity you don't recognise, and email support@passcode.sh if you find any. Mention the key's prefix, never the full key.