Skip to the content

DEVELOPERS · KEYS

API keys and security

Scopes, expiry and an address allow-list. A key is shown once and every use is in the audit log.

dsk_test_ · dsk_live_ · whsec_

What a key can do.

  • documents:readList and read documents and templates, the audit log, signed copies, reports
  • documents:writeSend, make templates, remind, void, start an embedded session
FIG. 01 · SCOPES
  • SignA key cannot sign for anyone
  • LinksNo response contains a signing link or a code
  • ScopesA key holds only scopes its creator holds
FIG. 02 · NEVER

Keep a key safe.

01

Server only

Never put a key in a web page or a mobile app.

02

One per integration

Revoke one without breaking another; revoking takes effect at once.

03

Audited

Every use is in the audit log with the key's name.

Questions

Quick answers.

What does a 401 mean?

The key is missing, wrong, revoked or lacks the scope. One answer covers all four on purpose.

Can a key expire?

Yes. Set an expiry when you make it.

Can I limit where it is used?

Yes. A key can be limited to addresses.

Make a scoped key.

Create an API key