7 days free, live today on a shared address. Plans from £3.99 a month, own domains from £14 a year. →
HomeHow it worksFeaturesPricingCompareGuides Sign in

Get started

Authentication

Bearer keys, what they can reach, how to revoke one, and the limits on each.

#Keys

A key looks like pk_live_ followed by a run of letters and numbers. It is tied to your account, so it sees every page on the account, including pages you were invited onto. It is shown once at creation. We store a SHA-256 hash and compare against that, which is why a lost key cannot be recovered, only replaced.

Authorization: Bearer pk_live_YOUR_KEY

#Revoking a key

Two kinds. A read key sees your numbers, pages and list. An edit key can also make draft pages and change pages, links and poplinks. Every key made before edit keys existed is a read key. Only the account owner can make an edit key, it is shown once like any other, and every change it makes is in the audit log on the Team screen.

On the API page, every key shows when it was last used. Revoke stops it immediately; the next request with it gets a 401. Make a new one first if a script depends on it.

Revoke a key the moment you think it has been seen by anyone else. For a read key the blast radius is your numbers and your email list; for an edit key it is your pages too.

#Limits

WhereLimitWindow
Any endpoint, per key60 requestsan hour
Any change (edit key), per key30 changesan hour, inside the 60
POST /api/v1/scan, per key20 scansan hour, inside the 60
The public scanner at /scan, per address10 scansa minute

Over the limit you get a 429 with a retry-after header in seconds and the same number in the body, in words. See Error handling.

#What a key cannot do

  • Change anything at all, if it is a read key.
  • Publish a page, change its address, point a domain at it, or change Shield or crawler mode without "confirm": true.
  • Put a page live that has no active domain.
  • Sign in as you, or reach the dashboard.
  • See billing, invoices or the card on file.
  • See another account. A key only ever returns pages the account can open.