Core concept
One API key
Neuctra Authix issues one kind of API key. It grants full account authority, so keep it on a trusted server.
Keep the key on your server
The key grants full account authority across users and app data.
| Property | API key | |
|---|---|---|
| Prefix | ak_live_… | Account API key |
| Where to use | Trusted server only | Never in browser or mobile code |
| Access | All operations available to the account | Every app, user, and record |
What a key looks like
Only the tail is secret. The prefix is a lookup handle and is safe to put in a log line.
ak_live_a1b2c3d4_9f8e7d6c5b4a39281706f5e4d3c2b1a09f8e7d6c5b4a3928
│ │ │ └── 48 hex characters — the only API part
│ │ └── lookup handle, safe to log
│ └── environment: live or test
└── one account API keyAt rest the server stores only a SHA-256 hash of the key, alongside the prefix and last four characters. Nobody — including you — can recover a key after it is issued, which is why the dashboard shows it exactly once.
Using the key safely
1// Server only — full account authority
2const authixAdmin = new NeuctraAuthix({
3 appId: APP_ID,
4 apiKey: process.env.AUTHIX_API_KEY,
5});Only trusted server code should receive an API key. Browser and mobile applications should call your own backend, which keeps the key private.
Why the key must stay private
A leaked key can access every user and record available to your account.
Treat it as an account credential
Do not put it in a browser bundle, mobile binary, source control, or a client-exposed environment variable. Route browser actions through a backend you control.
If it is exposed, revoke it and generate a replacement immediately.
Using SDKs
Configure server-side SDK clients with the apiKey field.
Use a backend endpoint or a trusted server SDK integration for work initiated by browser or mobile code.
When the key is wrong for the endpoint
A 403 means the caller is not authorized for that operation.
{
"success": false,
"message": "This endpoint requires an API key.",
"code": "INSUFFICIENT_SCOPE",
"hint": "Keep the account API key in trusted server-side code."
}Each SDK raises this as a distinct type — InsufficientScopeError — so you can handle it separately from a wrong password. In practice it almost always means the call belongs on your server.
Rotating a key
- Create the replacement in the dashboard first.
- Deploy it everywhere the old key is used. Both keys work during this window, so there is no outage.
- Revoke the old key. Revocation takes effect on the next request — there is no cache to wait out.
Rotate an API key immediately if
- It was committed to a repository, even a private one.
- It appeared in a client bundle — including via a
NEXT_PUBLIC_,VITE_or--dart-definevariable. - It was pasted into a log, a ticket, or a chat message.
Related