Authentication
Bearer tokens
All API requests use bearer tokens in the Authorization header:
Authorization: Bearer sk_live_abc123...
Token types
| Prefix | Purpose |
|---|---|
sk_live_ | Server-side, full access |
pk_live_ | Public, frontend-safe |
sk_test_ | Sandbox, no real charges |
Rotation
Rotate tokens via Dashboard → API keys. Old tokens expire 24h after rotation.