Skip to main content
Every request needs an API key in the x-api-key header.
A request without a valid key, or from a deactivated account, gets 401. There is no test mode: every key is live, and requests to charged endpoints are billed.

Keys

Create and manage keys under API keys in the dashboard.
  • A key is vpr_live_ followed by 64 hexadecimal characters.
  • The full key is shown once, when you create it. Only a fingerprint is stored, so a lost key cannot be recovered: create a new one.
  • Every key on your account draws on the same credit balance and has access to the same products.
  • You can rename a key and give it an expiry date. After that date it no longer works.
  • Revoking a key cannot be undone. A revoked key can keep working for up to 60 seconds.
To replace a key, create the new one, deploy it, then revoke the old one.

Keeping keys safe

Call the API from your server. A key in browser code, a mobile app or a public repository can be copied and used against your balance. Keep it in an environment variable or a secrets manager.