Skip to main content

Authentication

Every request to the Metaventus API is authenticated with a secret API key sent in the X-API-Key HTTP header:

X-API-Key: YOUR_SECRET_KEY
Plan required

Creating API keys requires a professional plan. On the free plan the API is not open: change plan from Billing → Subscription, or write to us if your case does not fit the boxes.

Key types and scopes​

Keys are created in Admin center → API keys in your workspace:

  • Secret key (sk_live_… in production, sk_test_… elsewhere): server-to-server use only. This is the key that reaches the API documented here.
  • Publishable key (pk_live_… / pk_test_…): meant for browser-side integrations (widgets, public forms). It does not open the endpoints in this reference.
  • Every key can be limited by scopes, restricted to IP addresses and given an expiry date; rotation happens without downtime — create the new key before revoking the old one.

A key acts within your account: whatever it creates belongs to your account and to the workspace the key is attached to.

Good practice​

  • Never share your key, and never expose it on the client side.
  • Store it in a server-side environment variable.
  • Revoke and reissue a compromised key immediately.
  • Use one key per environment (test / production).
warning

A request without a valid X-API-Key header returns 401 Unauthorized.