Key Principles
Project Scoping
Each API key is scoped to a specific project and cannot access resources across projects. This provides a simplified permission model for client applications.Read-Only Access
API keys provide read-only access. Content and components are limited to published versions:- Draft content requires JWT authentication with appropriate user roles
- Draft content types (
/types?draft=true) and the draft package (/packages/draft) can be read with an API key - Keys can be revoked at any time
- Designed specifically for production content delivery
Client Integration
API keys are designed for client-side applications:- Easily integrates with mobile and web applications
- Used as header parameter (
x-api-key) in API requests - No token refresh or expiration management required
Security
- Cannot create or modify resources
- Content and components limited to published versions
- No access to administrative functions
- Activity is logged and monitored
The API Key Object
string
Unique identifier
string
Descriptive name for the key (e.g., “iOS App Production”)
string
The actual API key value (only shown at creation time)
string
Status:
active or revokedstring
Last time the key was used (ISO 8601 format)
string
ID of the user who created the key
string
Creation timestamp (ISO 8601 format)
string
Last update timestamp (ISO 8601 format)
Example Object
Client API Endpoints
For the complete list of endpoints accessible via API keys, see the Client API Endpoints section in the Authentication documentation.Using API Keys
Include the API key in thex-api-key header: