Get started

API keys and scopes

Markdown

Keys look like sk_sceniq_.... Send one with every request:

Authorization: Bearer sk_sceniq_YOUR_KEY

X-Api-Key: sk_sceniq_YOUR_KEY works too. A missing key answers 401 unauthenticated; an unknown, revoked or expired key answers 401 invalid_api_key.

One key, one creator

A key is bound to the creator who made it. It reaches that creator's guides and profile and nothing else: not the store, not buyers, not other creators. An id that belongs to someone else answers 404 not_found, exactly like an id that does not exist, so ids never reveal what exists.

Scopes

ScopeCanTypical use
readEvery read operation (GET).Reports, checks, link health.
writeEverything read can, plus every write.Agents building and editing guides.
publishEverything write can, plus publish_changes. Only together with read and write.An agent that may publish a live guide's changes when the creator asks.

A write with a read-only key, or publish_changes without the publish option, answers 403 api_scope_required. Each operation's page shows the scope it needs.

What stays with the creator

No key can do these, whatever its scope. They answer 403 api_key_not_allowed if a function behind them is ever reached with a key:

  • putting a new guide on sale (its first publish) and archiving a guide,
  • publishing, unpublishing or rolling back the sales page,
  • store visibility and the store review,
  • accepting the creator agreement (until then, price changes and publishes answer 409 agreement_outdated),
  • payouts, Stripe Connect, referrals and the account itself,
  • making and revoking keys.

get_guide_readiness lists the clicks left for the creator in handoff, with their studio links.

Keeping keys safe

  • Keep the key in an environment variable or your agent's secret store. Never paste it into a prompt, a chat or a repository.
  • Give each agent its own key with a name you recognise, so you can revoke one without the others.
  • Set an expiry for short jobs. Revoke a key in the studio the moment you stop using it.
  • Every write through a key is marked on the guide, and the store review team sees it.