/v1/*. They are scoped to one project and one environment.
Key format
Send a key
Use the standard bearer header:401. Raw credentials and authorization headers are never written to logs.
Secret handling
- Keep keys in a server-side environment or secret manager.
- Use a different key per service when independent revocation matters.
- Never expose a key in browser JavaScript, mobile app binaries, logs, or support screenshots.
- Rotate keys by creating the replacement before revoking the old one.
Key status
A key can beACTIVE or REVOKED. Revocation does not delete historical usage or ledger data. The dashboard shows when a key was last used, so you can confirm traffic has moved before retiring a replacement.