Authentication
Every request to the Metaventus API is authenticated with a secret API key sent in the
X-API-Key HTTP header:
X-API-Key: YOUR_SECRET_KEY
Plan required
Creating API keys requires a professional plan. On the free plan the API is not open: change plan from Billing → Subscription, or write to us if your case does not fit the boxes.
Key types and scopes
Keys are created in Admin center → API keys in your workspace:
- Secret key (
sk_live_…in production,sk_test_…elsewhere): server-to-server use only. This is the key that reaches the API documented here. - Publishable key (
pk_live_…/pk_test_…): meant for browser-side integrations (widgets, public forms). It does not open the endpoints in this reference. - Every key can be limited by scopes, restricted to IP addresses and given an expiry date; rotation happens without downtime — create the new key before revoking the old one.
A key acts within your account: whatever it creates belongs to your account and to the workspace the key is attached to.
Good practice
- Never share your key, and never expose it on the client side.
- Store it in a server-side environment variable.
- Revoke and reissue a compromised key immediately.
- Use one key per environment (test / production).
warning
A request without a valid X-API-Key header returns 401 Unauthorized.