Passing API Keys
You can authenticate by providing your API key in one of two ways:1. HTTP Header
2. Query Parameter
We recommend using the x-api-key header for better security.
API Key Scopes
- Company-scoped keys – provide access across all projects within your organization. Use when building integrations that span multiple projects.
- Project-scoped keys – limited to a single project. Use when isolating access for specific applications, environments, or teams.
Best Practices
- Keep your API keys secret and never expose them in client-side code.
- Rotate keys regularly.
- Use project-scoped keys where possible to limit risk.
