Create and manage API keys
An API key proves a request comes from your account. Every request sends it in the Authorization header. You manage keys on the Developers page.
Create a key
- Open Developers, then API keys
Choose Test mode or Live mode at the top right. Keys belong to one mode.
- Select Create key and give it a name
Name it after where it will run, such as Production server. Optionally set an expiry date or limit it to your server's IP addresses.
- Confirm it’s you (live keys only)
Enter your password. If you sign in with Google, Apple or Microsoft, enter the 6-digit code we email you.
- Copy the key and store it
The key is shown once. Notriv keeps only a fingerprint of it, so it can't be shown again. Tick I've saved this key to close.
Store it safely
Put the key in an environment variable or secrets manager on your server and read it from there:
const notriv = new Notriv(process.env.NOTRIV_SECRET_KEY)Key options
| Option | What it does |
|---|---|
| Expires after | The key stops working after 30 days, 90 days or 1 year. Leave as Never for long-running servers. |
| Only allow these IPs | Requests from any other address get 403 ip_not_allowed. Use your servers’ fixed outbound IPs. |
Roll a key
Rolling replaces a key without downtime. Select Roll: you get a new key, and the old one keeps working for 24 hours so you can update your servers. Roll a key whenever someone who had it leaves, or if it might have been exposed.
Revoke a key
Select Revoke. The key stops working immediately and can't be restored.
Security alerts
- The account owner is emailed whenever a live key is created, rolled or revoked.
- Each key shows when and from which IP address it was last used.
- Every key change is recorded in your account's audit log.