Docs / Getting started
API Keys
Create, scope, rotate and protect the keys that authenticate your calls to Gurdx.
Live and test keys#
| Key | Prefix | Use for |
|---|---|---|
| Live | gx_live_ |
Production traffic. Counts against your quota and can raise events. |
| Test | gx_test_ |
Development and CI. Free, fake-but-well-formed data, never raises events. |
You can have several keys per account, for example one per application or environment, so a leak in one place does not force you to change everything. See Development environment.
Creating a key#
- Sign in to the dashboard at https://gurdx.cretip.com/app.
- Open the API keys page and create a key, choosing live or test.
- Copy it immediately and store it in a secret manager or environment variable.
Use the key as described in Authentication.
Authorized hosts#
You can restrict your account to a list of hosts. When the list is not empty, a request is accepted only if:
- the host of its
OriginorRefererheader is on the list, or - the caller's IP address is on the list.
Otherwise the API returns error 113 domain_not_whitelisted. Server-side calls usually carry no Origin, so list your server IP addresses. An empty list allows everything.
| Setup | List |
|---|---|
| Backend on fixed IPs | The server IPs |
| Browser calls with a test key | The site's domain |
Protecting your key#
Warning: Anyone who has a live key can spend your quota and read your data. Treat it like a password.
- Never embed a live key in JavaScript, mobile apps or HTML. Call Gurdx from your backend.
- Do not commit keys to Git. Use
.envfiles that are ignored, or a secret manager. - Prefer the
Authorization: Bearerheader to?key=so the key stays out of logs and referrers. - Use separate keys per environment and per service.
- Restrict authorized hosts wherever your traffic comes from a known place.
Rotating a key#
Rotate on a schedule, when someone leaves the team, or immediately after a suspected leak:
- Create a new key.
- Deploy it to your applications.
- Check in the dashboard that the old key's last-used time stops advancing.
- Delete the old key.
Requests with a deleted key return error 101 invalid_key.
If a key leaks#
Delete it at once, create a replacement and review recent usage in the dashboard for unexpected traffic. Rate limits (error 106) and your quota (error 103) cap the damage, but do not rely on them.
Common errors#
| Error | Cause |
|---|---|
| 101 | Missing, mistyped or deleted key |
| 102 | The account is inactive |
| 113 | Host or IP not in the authorized hosts |
| 127 | No active trial or subscription |
See the full list on Error codes.
Found a mistake? Tell us on the contact page. Contact