Skip to main content
New project keys begin with mbn_test_ or mbn_live_. The full secret is revealed once and is never stored in recoverable form.

Production checklist

  • Create one key per service and environment.
  • Grant only the required permissions.
  • Restrict models and endpoints when useful.
  • Store the key in a server-side secret manager.
  • Set an expiry for temporary access.
  • Rotate before revoking an active key.
Use a service account when the credential represents an application or automation instead of a human user.

Rotate without downtime

1

Create the new key

Create a second key with the same settings and store it in your secret manager.
2

Deploy it

Roll the new key out to your service and confirm requests succeed.
3

Check the old key is idle

Watch Last used on the old key until it stops changing.
4

Revoke the old key

Revoking takes effect immediately, and the action is written to the audit log. Requests that still use it receive 401 with revoked_api_key.
Creating keys is rate limited (30 per hour per user), so plan bulk key creation instead of scripting it in a tight loop.
Legacy account keys that start with mby_ belong to a user account and are separate from project keys. Use project keys for new integrations.