security
API Key Validation
Authenticate requests by matching the provided key against a registry. Simple but effective.
registered keys3
last result-
Key Registry (click to try)
Frontend App
sk_live_abc123
[read]
100/min
Admin Service
sk_live_xyz789
[read, write, delete]
1000/min
Analytics Worker
sk_live_def456
[read, write]
500/min
// validation log
No validations yet
How It Works
- Client sends key in Authorization header
- Server looks up key in registry/database
- If found → attach permissions, allow request
- If not found → 401 Unauthorized
Best Practices
- Prefix keys for identification (sk_live_...)
- Hash keys at rest (don't store plaintext)
- Rotate keys periodically
- Apply rate limits per key