Authentication
All Dashtray API requests require authentication via API keys.API Key Format
API keys follow this format:sk_- Prefix indicating this is a secret keytest- Environment marker (all keys currently usesk_test_regardless of plan)<random>- 48 hexadecimal characters (24 random bytes)
Using Your API Key
Include your API key in theAuthorization header:
Example Request
JavaScript/Fetch
Python/Requests
Managing API Keys
Generate a New Key
- Go to Dashboard → Settings → API Keys
- Click Generate New Key
- Enter a name (e.g., “Build Bot”, “Cline Agent”)
- Copy the full key immediately (displayed only once)
View Keys
Your API Keys page shows:- Key Preview - First 16 characters (e.g.,
sk_test_a1b2c3d4) — the rest is hidden - Name - Your custom name for the key
- Created - When the key was generated
- Last Used - When the key was last used (if at all)
Revoke a Key
Click Revoke on any key to permanently disable it. Revoked keys:- Stop working immediately
- Cannot be restored
- Should be regenerated if exposed
Security Best Practices
Environment Variables
Store your API key in an environment variable:Key Rotation
Rotate your API keys periodically:- Generate a new key
- Update your application to use the new key
- Revoke the old key after confirming everything works
Exposed Key
If a key is exposed:- Revoke immediately in the dashboard
- Generate a new key
- Update your application with the new key
- Monitor your account for unusual activity
Rate Limiting
Rate limits are based on your plan and applied per API key, per minute:
When rate limited, you’ll receive a
429 Too Many Requests response with a Retry-After: 60 header indicating when the window resets.
Troubleshooting
401 Unauthorized- Check the API key format (should start with
sk_) - Verify the
Authorizationheader is set correctly - Ensure the key hasn’t been revoked
- You’ve exceeded your rate limit
- Wait for the limit to reset (see the
Retry-Afterheader) - Upgrade your plan for higher limits