Skip to content

API & developers

API keys and key security

Creating, storing, rotating and revoking API keys — and exactly what to do if one leaks.

Last updated
Updated
Reading time
1 min read
On this page5
  1. Format
  2. Creating keys
  3. Keeping keys safe
  4. Rotating a key
  5. If a key leaks

API keys authenticate requests to the REST API. A key acts for your account — it can spend your balance — so treat it like a password.

Format

Keys start with pc_live_ followed by 32 letters and digits. Send yours in the Authorization header:

HTTP
Authorization: Bearer pc_live_…

In the dashboard we only ever show a key's first characters (for example pc_live_a1B2), so you can tell keys apart without exposing them.

Creating keys

Create keys on the API keys page, and give each a name that says where it's used: "production server", "staging", "price monitor". The full key is shown once, when you create it. We store only a one-way hash, so we can't show it again or recover it. Lost a key? Create a new one and revoke the old.

You can have up to 20 active keys.

Keeping keys safe

  • Keep keys on your server. Never ship them in a mobile app, in browser JavaScript, or in a public repository.
  • Load them from environment variables or a secrets manager, not from source code.
  • Use a separate key per environment or service, so you can revoke one without breaking the rest.
  • Keep an eye on last used on the API keys page. A key being used when you don't expect it is a reason to revoke it.

Rotating a key

  1. Create a new key.
  2. Deploy it everywhere the old one is used.
  3. Check that the old key's last-used time has stopped moving.
  4. Revoke the old key.

If a key leaks

Warning

Revoke it immediately on the API keys page. Revocation takes effect on the very next request: anything still using the key is rejected as unauthorized.

Then review your ledger and order history for activity you don't recognise, and email support@passcode.sh if you find any. Mention the key's prefix, never the full key.