Skip to main content

Authentication

All Dashtray API requests require authentication via API keys.

API Key Format

API keys follow this format:
Format breakdown:
  • sk_ - Prefix indicating this is a secret key
  • test - Environment marker (all keys currently use sk_test_ regardless of plan)
  • <random> - 48 hexadecimal characters (24 random bytes)
Only the SHA-256 hash of your key is stored server-side, so the full key is never recoverable — save it when it’s generated.

Using Your API Key

Include your API key in the Authorization header:

Example Request

JavaScript/Fetch

Python/Requests

Managing API Keys

Generate a New Key

  1. Go to Dashboard → Settings → API Keys
  2. Click Generate New Key
  3. Enter a name (e.g., “Build Bot”, “Cline Agent”)
  4. Copy the full key immediately (displayed only once)

View Keys

Your API Keys page shows:
  • Key Preview - First 16 characters (e.g., sk_test_a1b2c3d4) — the rest is hidden
  • Name - Your custom name for the key
  • Created - When the key was generated
  • Last Used - When the key was last used (if at all)

Revoke a Key

Click Revoke on any key to permanently disable it. Revoked keys:
  • Stop working immediately
  • Cannot be restored
  • Should be regenerated if exposed

Security Best Practices

Never commit API keys to version control. Use environment variables instead.

Environment Variables

Store your API key in an environment variable:
Access it in your code:

Key Rotation

Rotate your API keys periodically:
  1. Generate a new key
  2. Update your application to use the new key
  3. Revoke the old key after confirming everything works

Exposed Key

If a key is exposed:
  1. Revoke immediately in the dashboard
  2. Generate a new key
  3. Update your application with the new key
  4. Monitor your account for unusual activity

Rate Limiting

Rate limits are based on your plan and applied per API key, per minute: When rate limited, you’ll receive a 429 Too Many Requests response with a Retry-After: 60 header indicating when the window resets.

Troubleshooting

401 Unauthorized
  • Check the API key format (should start with sk_)
  • Verify the Authorization header is set correctly
  • Ensure the key hasn’t been revoked
429 Too Many Requests
  • You’ve exceeded your rate limit
  • Wait for the limit to reset (see the Retry-After header)
  • Upgrade your plan for higher limits