Authentication
API Key Types
Production Keys
Sandbox Keys
Getting Your API Key
Using Your API Key
HTTP Requests
SDK Authentication
TypeScript/Node.js
Python
Go
Security Best Practices
Never Commit API Keys
Use Environment Variables
Separate Keys for Each Environment
Rotate Keys Regularly
Restrict Key Permissions
Key Rotation
Manual Rotation
Automated Rotation
AWS Secrets Manager
HashiCorp Vault
IP Whitelisting
Rate Limiting
Plan
Requests/Minute
Requests/Hour
Burst
Handling Rate Limits
Webhook Signature Verification
API Key Monitoring
API Key Scopes
Read-Only Key
Agent-Specific Key
Admin Key
Testing Authentication
Verify API Key
SDK Health Check
Troubleshooting
Invalid API Key
Insufficient Permissions
Key Expired
Next Steps
Support
Last updated