Authentication and API keys
Every API request carries a secret key as a bearer token. Live keys send; test keys only record.
Send your API key in the Authorization header of every request to POST /v1/notifications and GET /v1/notifications/{id}. A key belongs to one project and can only reach that project's recipients and notifications.
Key format#
A key is sk_live_ or sk_test_ followed by 32 letters and digits. Anything else is rejected before Push looks it up.
⫻
format
Live and test keys#
- Live keys (
sk_live_…) send real notifications and count toward usage. - Test keys (
sk_test_…) run the same validation and record one attempt per connected browser, markedacceptedat once. They send nothing to any browser and never count toward usage. The recipient still needs at least one connected browser. - Both modes share the project's idempotency keys: a key used with a test request cannot be reused by a live request with a different body.
Creating and revoking keys#
- Create keys in the dashboard, under API keys in a project. Creating a project needs a verified email address.
- The full key is shown once, when you create it. Push stores only its SHA-256 hash and keeps the first 12 characters so you can tell keys apart. If you lose a key, revoke it and create a new one.
- Revoking is immediate: the next request with that key fails with
401 UNAUTHORIZED. It cannot be undone. - A project can have up to 10 active keys; revoked keys do not count. An account can have up to 10 projects.
- Each key shows when it was last used. That time is updated at most once a minute.
Keep keys on the server#
WarningKeys are server-side secrets. A request that carries an
Origin header, which every browser adds, is refused with 403 FORBIDDEN when it uses a live key. Test keys still work from a browser, so you can try the API there. A key placed in a mobile app or any other client could still be copied and used to notify your recipients and spend your credits. Call Push only from your server, and keep the key in an environment variable or a secret store.Authentication errors#
| Code | HTTP | When |
|---|---|---|
| UNAUTHORIZED | 401 | The Authorization header is missing, is not Bearer <key>, or the key is malformed, unknown or revoked. |
| FORBIDDEN | 403 | A live key was sent from a browser: the request carries an Origin header. Call the API from your server, or use a test key. |
| PROJECT_SUSPENDED | 403 | The key is valid but its project is suspended. Contact support. |
| RATE_LIMITED | 429 | Too many requests with invalid keys came from your IP address, or a valid key went over its rate limits. Wait for Retry-After seconds. |
NoteA suspended project is checked before rate limits, so its requests fail with
403 even when you are within your limits.