Reference

Authentication

Choose the credential class for the request path, then keep server secrets and browser activation flows separate.

Key classes

Server Test Keys start with sk_test_ and are for non-billable Test requests. Server Production Dry-run Keys start with sk_dry_ and are for non-billable pre-live validation. Server Production Keys start with sk_live_ and are for approved live server traffic. Browser Publishable Keys start with pk_publishable_ and are only for browser activation.

Keep sk_test_, sk_dry_, and sk_live_ values on your server. Never place server secret keys in browser bundles, HTML, mobile apps, or public repositories.

Browser activation

A browser sends its pk_publishable_ key in the POST /v1/browser/activate request body together with an allowed Origin. A successful activation returns a short-lived activation_token bound to that project and origin.

Use the returned activation token for browser-authorized /v1 requests. Do not send the raw publishable key as Authorization for placements, jobs, decisions, beacons, consent, or project configuration.

Permissions and origins

Configure every local, staging, preview, and production browser origin on the publishable key in the dashboard. Activation rejects an Origin that is not configured for that key.

A valid server secret key or a valid browser activation token is required for the authenticated /v1 routes. The hosted renderer script and issued render-frame URLs do not use an Authorization header.

Create and rotate server keys

Copy the full server secret when it is created or rotated. Masked previews only identify a key; they cannot authenticate a request and cannot be used to recover its value.

Update your server configuration before retiring the previous credential. Treat revoked keys as unavailable immediately unless the dashboard explicitly shows a grace deadline.

Use test credentials for integration checks and sk_dry_ for non-billable production dry-run. Live traffic requires completed payout setup and activated delivery. Browser Publishable Keys remain separate from all server key classes.

Dry-run is selected by credential class. Do not send production_dry_run, production_billing_dry_run, billing_suppressed, or production_live_approved in request bodies.

Need help with your integration?

Share the affected endpoint, request ID, and the behavior you expected. Leave out keys and user content.

Contact the team