Skip to content

Authentication ​

The operations that extract data or read your account take an API key in the Authorization header:

http
Authorization: Bearer <your key>

The price list and the API's status are public: they need no key.

Keys per workspace ​

Each key belongs to a workspace of your organization, and stays active even after whoever created it leaves the organization. Create, rotate and revoke keys in the panel, under API Keys.

Live and test keys ​

Keys start with dso_live_v1_ or dso_test_v1_. Both call the engines and use credits: a test key keeps your environments' usage apart, not calls free.

Keep the key on your server ​

  • Read the key from an environment variable or a secrets vault; never write it in the code.
  • Do not put the key in a website or app that runs on the user's device: whoever sees it can use it. Call the API from your server.
  • If a key leaks, revoke it in the panel and create another.
  • The reference's Try it keeps the key in the browser tab only, and sends it only to the API.

When the key fails ​

The API answers 401 when the key is missing, malformed, unknown, revoked or expired. Nothing runs and nothing is charged.