Guides
Authentication
Every request is authenticated with an API key sent as a bearer token. Keys carry scopes, so each integration gets only the access it needs.
Sending the key
Authorization: Bearer mk_live_xxxxxxxxxxxxxxxxxxxxxxxx
Keys that start with mk_live_ act on production data. Keys that start with mk_test_ act on the sandbox and cannot reach production.
Scopes
| Scope | Allows |
|---|---|
projects:read | List and read projects. |
deployments:write | Create and cancel deployments. |
billing:read | Read invoices and usage. |
webhooks:manage | Create, update and delete webhook endpoints. |
Grant the smallest set that works. A key used by a CI job usually needs only projects:read and deployments:write.
Rotating a key without downtime
- Create a second key with the same scopes.
- Deploy the new key to every service that uses the old one.
- Check the Last used column in the portal. When the old key has been idle for a day, revoke it.
Never commit keys to a repository. If a key leaks, revoke it first and investigate afterwards. Revocation takes effect within a few seconds.
Keeping keys safe
- Load keys from the environment or a secrets manager, not from source files.
- Use a separate key per service so you can revoke one without touching the others.
- Rotate keys at least once a year, and whenever someone with access leaves the team.