API keys
Diese Seite ist noch nicht auf Deutsch verfügbar. Sie sehen die englische Fassung.
API keys are project-scoped and come in two types:
| Type | Used for | Accepted by |
|---|---|---|
secret (nrn_sk_...) | Server-side calls to Platform API, Service API, and MCP. | Platform API, Service API, MCP |
publishable (nrn_pk_...) | Browser-facing surfaces (e.g. the web widget). | Not accepted by Service API or MCP. |
A key is the grant — presenting a valid secret key resolves directly to
{ apiKeyId, projectId, organizationId, keyType } with no further membership check. There is no
concept of “this key acts as user X” — it acts for the project it was minted under.
Minting a key
Section titled “Minting a key”Where you mint a key depends on the project type:
- Regular projects — a hotline or app project you manage in the dashboard at
ui.testing.nairon.cloud. Open the project and go to Setup → API keys to mint a secret key for the Service API and MCP. - Platform projects — mint Platform API and Service API keys in the
platform console at
platform.testing.nairon.cloud, on the project’s API Keys page.
Then, on that page:
- Click Create key, give it a name, and copy the plaintext value immediately — it is shown only once. Nairon stores only a SHA-256 hash plus the key’s prefix/last-4 for display.
- Revoke a key from the same page at any time; revocation is immediate.
Verifying a key
Section titled “Verifying a key”curl https://api.testing.nairon.cloud/v1/me -H "Authorization: Bearer NAIRON_API_KEY"{"apiKeyId": "...", "projectId": "...", "organizationId": "...", "keyType": "secret"}Never commit real keys
Section titled “Never commit real keys”Treat nrn_sk_... keys like any other credential — never commit them, and never embed a real key
in a shared code sample. All examples in this documentation use the placeholder NAIRON_API_KEY.
