Docs / Platform
API keys
Publishable and secret keys, restrictions, and rotation.
Beta access remains invite-only; request access. After your account is enabled, use the account portal to create, restrict, and revoke keys. A newly created key is shown once. Lost keys cannot be recovered; create a replacement and revoke the old key.
| Key | Use | Where to keep it |
|---|---|---|
pk_… |
Logo images | Browser image URLs or public app configuration |
sk_… |
Search and company data | Server environment or secret manager |
Keys are stored as SHA-256 hashes. Save a new key securely; it is not retrievable from its hash. Authentication results are cached per Worker instance for up to 60 seconds, so revocation is not instantaneous. Previously cached images can remain visible longer.
Sign in at the account portal with a one-time email link. Links expire after 15 minutes and are single-use; account sessions expire after 14 days and are stored for the current browser tab. The portal shows recent usage, lets you issue keys, edit publishable-key domains, and revoke keys. It does not expose an existing key again.
Domain restrictions
A publishable key can be restricted to configured domains and their subdomains. Checks use Referer or Origin when present. Requests without either header are allowed to support email and native clients; restrictions discourage key reuse but are not a strict access boundary.
Never send us an entire secret key in a support message. Provide the account email and sanitized request details instead.
Need a hand? Get help · Technical content reviewed October 2, 2026