Meretrix Dev / docs

Guides

Authentication

Every request is authenticated with an API key sent as a bearer token. Keys carry scopes, so each integration gets only the access it needs.

Sending the key

Authorization: Bearer mk_live_xxxxxxxxxxxxxxxxxxxxxxxx

Keys that start with mk_live_ act on production data. Keys that start with mk_test_ act on the sandbox and cannot reach production.

Scopes

ScopeAllows
projects:readList and read projects.
deployments:writeCreate and cancel deployments.
billing:readRead invoices and usage.
webhooks:manageCreate, update and delete webhook endpoints.

Grant the smallest set that works. A key used by a CI job usually needs only projects:read and deployments:write.

Rotating a key without downtime

  1. Create a second key with the same scopes.
  2. Deploy the new key to every service that uses the old one.
  3. Check the Last used column in the portal. When the old key has been idle for a day, revoke it.

Never commit keys to a repository. If a key leaks, revoke it first and investigate afterwards. Revocation takes effect within a few seconds.

Keeping keys safe