API key management
you can read at a glance
One key per environment, bearer token authentication, and prefixes that say which is which. A live key pasted into a test config is a mistake the naming makes visible.
Sandbox profiles are simulated and cost nothing. No card, no commitment.
Choose the environment. We issue the key.
Five choices. One call. The prefix tells anyone reading which one they are holding.ENVIRONMENT
PREFIX
SCOPE
ROTATION
LABEL
key_9Fw3mT4 minutes ago# A test key, as one call
POST /v1/keys { "env": "test", "prefix": "sk_test_", "scope": "account", "rotate": "manual", "label": "billing-service" }
TELLING THEM APART
A prefix is a control, not a convention.
What the naming actually prevents.
You can see which it is
sk_test_ and sk_live_ are visible in a log, a commit, a screenshot and a support ticket.
So can a linter
A pre-commit hook that refuses sk_live_ is three lines, because the prefix is stable.
So can the platform
A test key reaches simulated resources and cannot reach live ones. That is enforced, not advised.
And rotation is one call
The old key stops, the new one starts, and nothing else changes.
The whole point is that a mistake is visible before it is expensive.
WHO IT IS FOR
For every team that has ever leaked a credential
Nobody leaks a key on purpose. They leak it because it looked like a string, and nothing about it said what it could do.
A credential you can identify. Take a test key and try to break it, at no cost.
WHAT YOU GET
A key that announces itself, before anything goes wrong
What a key is, what it can reach and when it was last used all come from the API.
- Prefixes
- sk_test_ and sk_live_, so a key is identifiable on sight in a log, a commit or a screenshot.
- Environments
- One key per environment. A test key reaches simulated resources and cannot reach live ones.
- Scope
- The whole account, or one capability where a key is going somewhere you do not fully control.
- Rotation
- Issue the new one, retire the old one. Both are calls and neither needs a maintenance window.
- Events
- Webhooks on issued, first used, rotated and revoked.
- Auth
- Bearer token on every request. One scheme across every capability, with nothing per-endpoint to remember.
- Retries
- Issuing takes an idempotency key, so a retried request returns the original key rather than minting a second.
- Errors
- One shape everywhere: a type, a code, a message, the parameter at fault and a link. Never a bare 500 with a stack trace.
- Reference
- One published OpenAPI specification. The server validates against it, the SDKs are generated from it and the sandbox mocks from it.
WORKS WITH
Switch on the next one the same way
Nothing new to sign and nothing new to integrate. The same call with a different noun.
QUESTIONS
API keys on Telyne
Why are keys prefixed?
So a key is identifiable on sight. sk_test_ and sk_live_ are visible in a log, a commit, a screenshot or a support ticket, which turns a leaked credential from a silent problem into an obvious one.
Can a test key reach live resources?
No. That is enforced by the platform rather than left to discipline. A test key reaches simulated resources and nothing else, which is why it is safe to put in a pipeline.
How does rotation work?
Issue the new key, retire the old one. Both are calls, neither needs a maintenance window, and the events tell you when the old one stops being used.
Can I give someone a key that cannot do everything?
Yes. A key is scoped to the whole account or to one capability, so a contractor or a service can be given exactly what it needs and nothing else.
What authentication scheme is used?
Bearer tokens, on every request, across every capability. There is one scheme to learn and nothing per-endpoint to remember.
Take a test key before you have decided anything
No approval step and nothing to sign. The sandbox is open now, and production access opens in the order requests arrive.
One email at launch. Nothing else, and unsubscribe in one click.
We send a link to confirm the address. Unconfirmed addresses are deleted after 30 days.
Complex requirement or an existing estate to move? Talk to us.