Skip to main content
API authentication requires two values from a project-scoped API key.
string
required
Bearer followed by the access key. Access keys begin with APTRANET_.
string
required
The current secret for the access key.

How authentication works

The Gateway hashes the supplied secret, compares it with the key record, confirms that the key is active, and loads its project and permission document. Product routes then authorize the requested action.

Store credentials

  • Use a managed secret store or protected deployment secret.
  • Keep access keys and secrets out of source control, frontend bundles, screenshots, and logs.
  • Use separate keys for each workload and environment.
  • Scope each key to the minimum operations it performs.

Rotate a secret

Rolling a secret replaces the current secret immediately. For deployments that need overlap, create a second key with the same minimum permissions, deploy it, verify it, and then disable and delete the old key.
Never send API credentials to a hostname other than api.aptranet.com. Aptranet support will not ask you for a secret.