Skip to main content
An API key (apy_*) is your Party’s server-side credential; its secret starts with sk_ntl_. A request made with it acts as your party, limited to the scopes the key was created with. Keep it on servers you control, never in a browser or client app.

Scopes

A key carries a scope list; omit scopes and it gets every scope, so pass a narrow list for narrow jobs. A call outside the key’s scopes is rejected.

Keys and agents

An API key moves money as a party action and cannot act as an agent. A credential that acts as an agent is an Agent key. See Authentication for the full credential model.

Lifecycle

Create a key with POST /api-keys. It is ACTIVE until you revoke it with DELETE /api-keys/{keyId}, then REVOKED. Create and revoke keys from a user session; a key cannot create or revoke keys.

Secrets

The secret is returned once, on creation, and can never be read again. Revoking a key invalidates it immediately.