Docs / Start here

API keys and auth

How keys work, how to keep them safe, and what to do if one leaks.

Every request to /v1/check and /v1/job/{id} carries your key in the Authorization header:

Authorization: Bearer pij_live_YOUR_KEY

About keys

Keep keys safe

If a key leaksIf a key leaks, open the dashboard, go to API keys, and click Revoke beside it. It stops working immediately. Then create a new one. Revoking cannot be undone, and that is the point.

Who can create keys

Only the workspace owner and admins. Editors and members can use the dashboard but do not see keys.

Dashboard sign-in is separate

People sign in to the dashboard with an emailed code. That is not an API key. The code expires in 10 minutes and works once.