Docs / Start here
API keys and auth
How keys work, how to keep them safe, and what to do if one leaks.
Every request to /v1/check and /v1/job/{id} carries your key in the Authorization header:
Authorization: Bearer pij_live_YOUR_KEY
About keys
- Keys start with
pij_live_and are long and random. - We store only a one-way fingerprint. We cannot show a key again. If you lose it, create a new one and revoke the old.
- A workspace can have up to five active keys. Use one per system (CMS, mobile shortcut, spreadsheet) so you can revoke one without breaking the rest.
- All keys in a workspace share the same 100-check monthly allowance.
Keep keys safe
- Keep keys on your server, in an environment variable or secrets manager.
- Never put a key in a web page, a mobile app, a public repository, a screenshot, or the community forum.
- Never email a key. Share keys by a password manager.
If a key leaksIf a key leaks, open the dashboard, go to API keys, and click Revoke beside it. It stops working immediately. Then create a new one. Revoking cannot be undone, and that is the point.
Who can create keys
Only the workspace owner and admins. Editors and members can use the dashboard but do not see keys.
Dashboard sign-in is separate
People sign in to the dashboard with an emailed code. That is not an API key. The code expires in 10 minutes and works once.