Skip to main content
Every request needs an API key. The key also decides whether you reach sandbox or live.

Get a key

Create keys in the dashboard under API Keys. A key belongs to the environment the dashboard is switched to when you create it. The full key is shown once, so copy it then.

Send the key

Put the key in the x-api-key header.
A missing key returns 401 UNAUTHORIZED. An unrecognised or revoked key returns 401 INVALID_API_KEY.

Sandbox and live

The prefix tells you which environment a key belongs to. Both use the same host. Data never crosses environments: a sandbox key can’t see live devices, and a live key can’t see sandbox devices. Live keys only work once your account is enabled for live. Until then they return 403 LIVE_ACCESS_DISABLED. To move to production, swap your sk_test_ key for an sk_live_ key and drop sandbox=true from your Link UI URLs. Nothing else changes.

Check the environment

Every authenticated response reports the environment that served it in meta.environment.

Rate limits

If you send too many requests, you get 429 RATE_LIMIT_EXCEEDED. Responses don’t include rate-limit headers, so retry with exponential backoff.

Keep keys safe

  • Call the API from your server. Never ship a key in a browser or mobile app.
  • Load keys from environment variables or a secrets manager. Don’t commit them.
  • Use a separate key per service, so you can revoke one without breaking the others.
  • To rotate, create a new key, deploy it, then delete the old one in the dashboard. A deleted key stops working.

Next steps

Link UI

Let end users connect their devices.

Error codes

Every authentication and access error.