Core concept

One API key

Neuctra Authix issues one kind of API key. It grants full account authority, so keep it on a trusted server.

Keep the key on your server

The key grants full account authority across users and app data.

PropertyAPI key
Prefixak_live_…Account API key
Where to useTrusted server onlyNever in browser or mobile code
AccessAll operations available to the accountEvery app, user, and record

What a key looks like

Only the tail is secret. The prefix is a lookup handle and is safe to put in a log line.

Bash
ak_live_a1b2c3d4_9f8e7d6c5b4a39281706f5e4d3c2b1a09f8e7d6c5b4a3928
│  │    │        └── 48 hex characters — the only API part
│  │    └── lookup handle, safe to log
│  └── environment: live or test
└── one account API key

At rest the server stores only a SHA-256 hash of the key, alongside the prefix and last four characters. Nobody — including you — can recover a key after it is issued, which is why the dashboard shows it exactly once.

Using the key safely

1// Server only — full account authority
2const authixAdmin = new NeuctraAuthix({
3  appId: APP_ID,
4  apiKey: process.env.AUTHIX_API_KEY,
5});

Only trusted server code should receive an API key. Browser and mobile applications should call your own backend, which keeps the key private.

Why the key must stay private

A leaked key can access every user and record available to your account.

Treat it as an account credential

Do not put it in a browser bundle, mobile binary, source control, or a client-exposed environment variable. Route browser actions through a backend you control.

If it is exposed, revoke it and generate a replacement immediately.

Using SDKs

Configure server-side SDK clients with the apiKey field.

Use a backend endpoint or a trusted server SDK integration for work initiated by browser or mobile code.

When the key is wrong for the endpoint

A 403 means the caller is not authorized for that operation.

Json
{
  "success": false,
  "message": "This endpoint requires an API key.",
  "code": "INSUFFICIENT_SCOPE",
  "hint": "Keep the account API key in trusted server-side code."
}

Each SDK raises this as a distinct type — InsufficientScopeError — so you can handle it separately from a wrong password. In practice it almost always means the call belongs on your server.

Rotating a key

  • Create the replacement in the dashboard first.
  • Deploy it everywhere the old key is used. Both keys work during this window, so there is no outage.
  • Revoke the old key. Revocation takes effect on the next request — there is no cache to wait out.

Rotate an API key immediately if

  • It was committed to a repository, even a private one.
  • It appeared in a client bundle — including via a NEXT_PUBLIC_, VITE_ or --dart-define variable.
  • It was pasted into a log, a ticket, or a chat message.

Related