Overview

Authentication

Secret keys for servers, publishable keys for browsers.

Key types

KeyPrefixWhere to use itScopes
Secret keyatl_sk_Your server only. Never ship it to a browser.Chosen when the key is created
Publishable keyatl_pk_The widget and browser SDK, from your allowed domains.feedback, events, identify

Sending the key

Header
Authorization: Bearer atl_sk_xxxxxxxxxxxxxxxx

Creating and revoking keys

In Feedback → Integrations, create a secret key, copy it once (only a hash is stored), and revoke it whenever you need to. The publishable key and its allowed domains are part of the widget settings.

Rate limits

KeyLimit
Secret600 requests / minute
Publishable120 requests / minute

Over the limit you get 429 rate_limited with a Retry-After: 60 header.