DEVELOPERS · KEYS
API keys and security
Scopes, expiry and an address allow-list. A key is shown once and every use is in the audit log.
dsk_test_ · dsk_live_ · whsec_
dsk_test_… practice data only
dsk_live_… real documents
whsec_… webhook secret, shown once
What a key can do.
- documents:readList and read documents and templates, the audit log, signed copies, reports
- documents:writeSend, make templates, remind, void, start an embedded session
- SignA key cannot sign for anyone
- LinksNo response contains a signing link or a code
- ScopesA key holds only scopes its creator holds
Keep a key safe.
01
Server only
Never put a key in a web page or a mobile app.
02
One per integration
Revoke one without breaking another; revoking takes effect at once.
03
Audited
Every use is in the audit log with the key's name.
Questions
Quick answers.
What does a 401 mean?
The key is missing, wrong, revoked or lacks the scope. One answer covers all four on purpose.
Can a key expire?
Yes. Set an expiry when you make it.
Can I limit where it is used?
Yes. A key can be limited to addresses.