Skip to content

Get started / Authentication and API keys

Authentication and API keys

Every API request carries a secret key as a bearer token. Live keys send; test keys only record.

Send your API key in the Authorization header of every request to POST /v1/notifications and GET /v1/notifications/{id}. A key belongs to one project and can only reach that project's recipients and notifications.

Authorization: Bearer sk_live_9fQ2…

Key format#

A key is sk_live_ or sk_test_ followed by 32 letters and digits. Anything else is rejected before Push looks it up.

⫻

format

sk_live_<32 letters and digits>sk_test_<32 letters and digits>

Live and test keys#

  • Live keys (sk_live_…) send real notifications and count toward usage.
  • Test keys (sk_test_…) run the same validation and record one attempt per connected browser, marked accepted at once. They send nothing to any browser and never count toward usage. The recipient still needs at least one connected browser.
  • Both modes share the project's idempotency keys: a key used with a test request cannot be reused by a live request with a different body.

Creating and revoking keys#

  • Create keys in the dashboard, under API keys in a project. Creating a project needs a verified email address.
  • The full key is shown once, when you create it. Push stores only its SHA-256 hash and keeps the first 12 characters so you can tell keys apart. If you lose a key, revoke it and create a new one.
  • Revoking is immediate: the next request with that key fails with 401 UNAUTHORIZED. It cannot be undone.
  • A project can have up to 10 active keys; revoked keys do not count. An account can have up to 10 projects.
  • Each key shows when it was last used. That time is updated at most once a minute.

Keep keys on the server#

WarningKeys are server-side secrets. A request that carries an Origin header, which every browser adds, is refused with 403 FORBIDDEN when it uses a live key. Test keys still work from a browser, so you can try the API there. A key placed in a mobile app or any other client could still be copied and used to notify your recipients and spend your credits. Call Push only from your server, and keep the key in an environment variable or a secret store.

Authentication errors#

CodeHTTPWhen
UNAUTHORIZED401The Authorization header is missing, is not Bearer <key>, or the key is malformed, unknown or revoked.
FORBIDDEN403A live key was sent from a browser: the request carries an Origin header. Call the API from your server, or use a test key.
PROJECT_SUSPENDED403The key is valid but its project is suspended. Contact support.
RATE_LIMITED429Too many requests with invalid keys came from your IP address, or a valid key went over its rate limits. Wait for Retry-After seconds.
NoteA suspended project is checked before rate limits, so its requests fail with 403 even when you are within your limits.