Skip to content
Gurdx

Docs / Getting started

API Keys

Create, scope, rotate and protect the keys that authenticate your calls to Gurdx.

Live and test keys#

Key Prefix Use for
Live gx_live_ Production traffic. Counts against your quota and can raise events.
Test gx_test_ Development and CI. Free, fake-but-well-formed data, never raises events.

You can have several keys per account, for example one per application or environment, so a leak in one place does not force you to change everything. See Development environment.

Creating a key#

  1. Sign in to the dashboard at https://gurdx.cretip.com/app.
  2. Open the API keys page and create a key, choosing live or test.
  3. Copy it immediately and store it in a secret manager or environment variable.

Use the key as described in Authentication.

Authorized hosts#

You can restrict your account to a list of hosts. When the list is not empty, a request is accepted only if:

  • the host of its Origin or Referer header is on the list, or
  • the caller's IP address is on the list.

Otherwise the API returns error 113 domain_not_whitelisted. Server-side calls usually carry no Origin, so list your server IP addresses. An empty list allows everything.

Setup List
Backend on fixed IPs The server IPs
Browser calls with a test key The site's domain

Protecting your key#

Warning: Anyone who has a live key can spend your quota and read your data. Treat it like a password.

  • Never embed a live key in JavaScript, mobile apps or HTML. Call Gurdx from your backend.
  • Do not commit keys to Git. Use .env files that are ignored, or a secret manager.
  • Prefer the Authorization: Bearer header to ?key= so the key stays out of logs and referrers.
  • Use separate keys per environment and per service.
  • Restrict authorized hosts wherever your traffic comes from a known place.

Rotating a key#

Rotate on a schedule, when someone leaves the team, or immediately after a suspected leak:

  1. Create a new key.
  2. Deploy it to your applications.
  3. Check in the dashboard that the old key's last-used time stops advancing.
  4. Delete the old key.

Requests with a deleted key return error 101 invalid_key.

If a key leaks#

Delete it at once, create a replacement and review recent usage in the dashboard for unexpected traffic. Rate limits (error 106) and your quota (error 103) cap the damage, but do not rely on them.

Common errors#

Error Cause
101 Missing, mistyped or deleted key
102 The account is inactive
113 Host or IP not in the authorized hosts
127 No active trial or subscription

See the full list on Error codes.

Found a mistake? Tell us on the contact page. Contact