Skip to content

API keys

API keys are project-scoped and come in two types:

TypeUsed forAccepted by
secret (nrn_sk_...)Server-side calls to Platform API, Service API, and MCP.Platform API, Service API, MCP
publishable (nrn_pk_...)Browser-facing surfaces (e.g. the web widget).Not accepted by Service API or MCP.

A key is the grant — presenting a valid secret key resolves directly to { apiKeyId, projectId, organizationId, keyType } with no further membership check. There is no concept of “this key acts as user X” — it acts for the project it was minted under.

Where you mint a key depends on the project type:

  • Regular projects — a hotline or app project you manage in the dashboard at ui.testing.nairon.cloud. Open the project and go to Setup → API keys to mint a secret key for the Service API and MCP.
  • Platform projects — mint Platform API and Service API keys in the platform console at platform.testing.nairon.cloud, on the project’s API Keys page.

Then, on that page:

  1. Click Create key, give it a name, and copy the plaintext value immediately — it is shown only once. Nairon stores only a SHA-256 hash plus the key’s prefix/last-4 for display.
  2. Revoke a key from the same page at any time; revocation is immediate.
Terminal window
curl https://api.testing.nairon.cloud/v1/me -H "Authorization: Bearer NAIRON_API_KEY"
{"apiKeyId": "...", "projectId": "...", "organizationId": "...", "keyType": "secret"}

Treat nrn_sk_... keys like any other credential — never commit them, and never embed a real key in a shared code sample. All examples in this documentation use the placeholder NAIRON_API_KEY.