API keys

An API key belongs to exactly one project and does what its scopes name. You can narrow it further to named models and operations, or confine it to one organisation.

Public and secret keys

There are two types, told apart by prefix. A public key (pk_) is safe to ship in a browser. Alone it is read-only and returns published content, and a signed-in user adds the scopes of their own role. A secret key (sk_) is for a server, and the API rejects one on any request that carries a browser's Origin header. Either kind is created inside a project and serves that project alone.

Scopes

Scopes set the kind of access a key has, such as records:read or running operations. The check is an allow-list, so a call whose scope the key lacks is refused. A scope permits a call and never widens which rows a query returns. Some scopes cannot be held by a public key at all, and asking for one is refused when the key is created.

Narrowing to models and operations

Two selectors on a key set which resources it reaches: model access and operation access. Both default to all, meaning everything the key's scopes cover, so narrowing is opt-in. Choose specific models and the typed fields for every other model disappear from the schema that key sees, and calls to them are denied. Choose specific operations and an unlisted operation's mutation is absent from the key's schema, introspection included.

Confinement to one organisation

A key can be confined to one organisation when it is created. It reads that organisation, everything beneath it and the rows shared across the project, and writes only its own. It must name at least one scope, cannot mint keys and is deleted with its organisation.

Rotation and later changes

Rotating a key keeps the old secret working for 24 hours. Revoking ends every secret immediately. Scopes, allowed models and the name can be edited on an existing key and take effect when saved. Key type, confinement and expiry are fixed at creation.

Read the detail

The API keys guide covers both key types, their scopes, restricting a key's reach and rotation.