Authentication
Every request to the Acme API is authenticated with a bearer token. This page covers creating a key, storing it safely, and rotating it without downtime.
Acme issues two kinds of keys. Secret keys (prefixed sk_live_) can read and write everything in your project and must only ever live on a server. Publishable keys (prefixed pk_live_) are safe to ship in a browser bundle and can only create client sessions.
Keys are scoped to a project, not to your account. Deleting a project revokes its keys immediately; removing a teammate does not, so treat offboarding as a reason to rotate.
Creating an API key
Create a key from the dashboard under Settings → API keys, then pass it as a bearer token on every request:
curl https://api.acme.dev/v1/projects \
-H "Authorization: Bearer $ACME_API_KEY"Note: the full secret is shown once, at creation. Acme stores only a hash, so a lost key cannot be recovered — it can only be rotated.
Rotating keys
Rotation is overlap, not replacement: create the new key, deploy it everywhere, and only then revoke the old one. Both keys stay valid during the window, so a slow rollout never turns into an outage.