Authentication
The operations that extract data or read your account take an API key in the Authorization header:
http
Authorization: Bearer <your key>The price list and the API's status are public: they need no key.
Keys per workspace
Each key belongs to a workspace of your organization, and stays active even after whoever created it leaves the organization. Create, rotate and revoke keys in the panel, under API Keys.
Live and test keys
Keys start with dso_live_v1_ or dso_test_v1_. Both call the engines and use credits: a test key keeps your environments' usage apart, not calls free.
Keep the key on your server
- Read the key from an environment variable or a secrets vault; never write it in the code.
- Do not put the key in a website or app that runs on the user's device: whoever sees it can use it. Call the API from your server.
- If a key leaks, revoke it in the panel and create another.
- The reference's Try it keeps the key in the browser tab only, and sends it only to the API.
When the key fails
The API answers 401 when the key is missing, malformed, unknown, revoked or expired. Nothing runs and nothing is charged.