Get started
API keys and scopes
Keys look like sk_sceniq_.... Send one with every request:
Authorization: Bearer sk_sceniq_YOUR_KEYX-Api-Key: sk_sceniq_YOUR_KEY works too. A missing key answers 401 unauthenticated; an unknown, revoked or expired key answers 401 invalid_api_key.
One key, one creator
A key is bound to the creator who made it. It reaches that creator's guides and profile and nothing else: not the store, not buyers, not other creators. An id that belongs to someone else answers 404 not_found, exactly like an id that does not exist, so ids never reveal what exists.
Scopes
| Scope | Can | Typical use |
|---|---|---|
read | Every read operation (GET). | Reports, checks, link health. |
write | Everything read can, plus every write. | Agents building and editing guides. |
publish | Everything write can, plus publish_changes. Only together with read and write. | An agent that may publish a live guide's changes when the creator asks. |
A write with a read-only key, or publish_changes without the publish option, answers 403 api_scope_required. Each operation's page shows the scope it needs.
What stays with the creator
No key can do these, whatever its scope. They answer 403 api_key_not_allowed if a function behind them is ever reached with a key:
- putting a new guide on sale (its first publish) and archiving a guide,
- publishing, unpublishing or rolling back the sales page,
- store visibility and the store review,
- accepting the creator agreement (until then, price changes and publishes answer
409 agreement_outdated), - payouts, Stripe Connect, referrals and the account itself,
- making and revoking keys.
get_guide_readiness lists the clicks left for the creator in handoff, with their studio links.
Keeping keys safe
- Keep the key in an environment variable or your agent's secret store. Never paste it into a prompt, a chat or a repository.
- Give each agent its own key with a name you recognise, so you can revoke one without the others.
- Set an expiry for short jobs. Revoke a key in the studio the moment you stop using it.
- Every write through a key is marked on the guide, and the store review team sees it.