Overview
Authentication
Secret keys for servers, publishable keys for browsers.
Key types
| Key | Prefix | Where to use it | Scopes |
|---|---|---|---|
| Secret key | atl_sk_ | Your server only. Never ship it to a browser. | Chosen when the key is created |
| Publishable key | atl_pk_ | The widget and browser SDK, from your allowed domains. | feedback, events, identify |
Sending the key
Header
Authorization: Bearer atl_sk_xxxxxxxxxxxxxxxxCreating and revoking keys
In Feedback → Integrations, create a secret key, copy it once (only a hash is stored), and revoke it whenever you need to. The publishable key and its allowed domains are part of the widget settings.
Rate limits
| Key | Limit |
|---|---|
| Secret | 600 requests / minute |
| Publishable | 120 requests / minute |
Over the limit you get 429 rate_limited with a Retry-After: 60 header.