# API keys and scopes

Keys look like `sk_sceniq_...`. Send one with every request:

```bash
Authorization: Bearer sk_sceniq_YOUR_KEY
```

`X-Api-Key: sk_sceniq_YOUR_KEY` works too. A missing key answers `401 unauthenticated`; an unknown, revoked or expired key answers `401 invalid_api_key`.

## One key, one creator

A key is bound to the creator who made it. It reaches that creator's guides and profile and nothing else: not the store, not buyers, not other creators. An id that belongs to someone else answers `404 not_found`, exactly like an id that does not exist, so ids never reveal what exists.

## Scopes

| Scope | Can | Typical use |
|---|---|---|
| `read` | Every read operation (`GET`). | Reports, checks, link health. |
| `write` | Everything `read` can, plus every write. | Agents building and editing guides. |
| `publish` | Everything `write` can, plus [publish_changes](https://developers.sceniq.earth/reference/publish_changes.md). Only together with read and write. | An agent that may publish a live guide's changes when the creator asks. |

A write with a read-only key, or `publish_changes` without the publish option, answers `403 api_scope_required`. Each operation's page shows the scope it needs.

## What stays with the creator

No key can do these, whatever its scope. They answer `403 api_key_not_allowed` if a function behind them is ever reached with a key:

- putting a new guide on sale (its first publish) and archiving a guide,
- publishing, unpublishing or rolling back the sales page,
- store visibility and the store review,
- accepting the creator agreement (until then, price changes and publishes answer `409 agreement_outdated`),
- payouts, Stripe Connect, referrals and the account itself,
- making and revoking keys.

[get_guide_readiness](https://developers.sceniq.earth/reference/get_guide_readiness.md) lists the clicks left for the creator in `handoff`, with their studio links.

## Keeping keys safe

- Keep the key in an environment variable or your agent's secret store. Never paste it into a prompt, a chat or a repository.
- Give each agent its own key with a name you recognise, so you can revoke one without the others.
- Set an expiry for short jobs. Revoke a key in the studio the moment you stop using it.
- Every write through a key is marked on the guide, and the store review team sees it.
