apy_*) is your Party’s server-side credential; its secret starts with sk_ntl_. A request made with it acts as your party, limited to the scopes the key was created with. Keep it on servers you control, never in a browser or client app.
Scopes
A key carries a scope list; omitscopes and it gets every scope, so pass a narrow list for narrow jobs. A call outside the key’s scopes is rejected.
Keys and agents
An API key moves money as a party action and cannot act as an agent. A credential that acts as an agent is an Agent key. See Authentication for the full credential model.Lifecycle
Create a key withPOST /api-keys. It is ACTIVE until you revoke it with DELETE /api-keys/{keyId}, then REVOKED. Create and revoke keys from a user session; a key cannot create or revoke keys.