Skip to main content
Keys are minted on API keys in Settings. vsk_live_ and vsk_test_ are different keys: the environment is inside the hashed value, so a test secret cannot be re-presented under a live prefix. What each can do is on Test keys and live keys. The examples in the API reference send the key as a bearer token. Put yours where each example’s placeholder is, or into the playground’s authorization field to send the request from the page.

Scopes

What an API key may do. A key’s scopes are chosen when it is minted and are immutable afterwards — there is no endpoint and no screen that can widen a key, by design, so a key that needs more access is replaced rather than edited. ⚠️ A key with NO scopes holds EVERY capability, not none: keys issued before scopes existed carry an empty list and are full keys, and nothing narrows them retroactively. Each operation publishes the one scope it requires as x-required-scope; a key that does not hold it is refused insufficient_scope (403) with a WWW-Authenticate header naming the scope, per RFC 6750 §3.1.