API Keys
All API requests require authentication via an API key.Getting Your API Key
- Go to Dashboard → Developer
- Click Create API Key
- Give it a descriptive name (e.g., “Production Server”, “Zapier Integration”)
- Copy the key immediately - it won’t be shown again
Using Your API Key
Include the key in theX-API-Key header:
Key Types
Test keys have the same capabilities but are clearly marked for non-production use.
Key Permissions
API keys have full access to your project. You cannot restrict permissions per-key (yet). Available operations:location:read- List and view locationslocation:create- Create new locationslocation:update- Update existing locationslocation:delete- Delete locationsfilter:read- List filtersfilter:create- Create filtersanalytics:read- View analytics data
Security Best Practices
Never expose keys in client-side code
Never expose keys in client-side code
API keys should only be used in server-side code. Never include them in:
- JavaScript running in the browser
- Mobile app source code
- Public repositories
Use environment variables
Use environment variables
Store API keys in environment variables, not in code:
Rotate keys periodically
Rotate keys periodically
Create a new key before revoking the old one:
- Create new API key
- Update your integrations to use new key
- Verify everything works
- Revoke the old key
Use separate keys per integration
Use separate keys per integration
Create different keys for different integrations. This makes it easier to:
- Track which integration is making requests
- Revoke access for a single integration without affecting others
- Debug issues
Revoking Keys
To revoke an API key:- Go to Dashboard → Developer → API Keys
- Find the key you want to revoke
- Click the Delete button
- Confirm revocation