Get started
Authentication
Bearer keys, what they can reach, how to revoke one, and the limits on each.
#Keys
A key looks like pk_live_ followed by a run of letters and numbers. It is
tied to your account, so it sees every page on the account, including pages you were
invited onto. It is shown once at creation. We store a SHA-256 hash and compare against
that, which is why a lost key cannot be recovered, only replaced.
Authorization: Bearer pk_live_YOUR_KEY
#Revoking a key
Two kinds. A read key sees your numbers, pages and list. An edit key can also make draft pages and change pages, links and poplinks. Every key made before edit keys existed is a read key. Only the account owner can make an edit key, it is shown once like any other, and every change it makes is in the audit log on the Team screen.
On the API page, every key shows when it was last used. Revoke stops it immediately; the next request with it gets a 401. Make a new one first if a script depends on it.
Revoke a key the moment you think it has been seen by anyone else. For a read key the blast radius is your numbers and your email list; for an edit key it is your pages too.
#Limits
| Where | Limit | Window |
|---|---|---|
| Any endpoint, per key | 60 requests | an hour |
| Any change (edit key), per key | 30 changes | an hour, inside the 60 |
POST /api/v1/scan, per key | 20 scans | an hour, inside the 60 |
| The public scanner at /scan, per address | 10 scans | a minute |
Over the limit you get a 429 with a retry-after header in
seconds and the same number in the body, in words. See
Error handling.
#What a key cannot do
- Change anything at all, if it is a read key.
- Publish a page, change its address, point a domain at it, or change Shield or crawler mode without
"confirm": true. - Put a page live that has no active domain.
- Sign in as you, or reach the dashboard.
- See billing, invoices or the card on file.
- See another account. A key only ever returns pages the account can open.