Skip to content
On this page

Guides

API keys

Each project has a publishable key for your apps and secret keys for your servers.

Two kinds of key

KindStarts withWhere it goesHow Shipbell keeps it
Publishablesb_pk_live_Your web and iOS appsIn plain text, so the admin can show it again
Secretsb_sk_live_Your servers onlyAs a SHA-256 hash. It is shown once

After the prefix, every key has 22 random letters and digits and a 6-character checksum.

Publishable keyComing soon

The publishable key identifies your project. Send it in the X-Project-Key header. It allows:

  • reading your project's configuration,
  • trading a sign-in token for a session,
  • opening the board from your app,
  • public reads, but only when your board is public or unlisted. On a private board, every read needs a session.

Requests from browsers are checked against your project's allowed origins. Apps outside a browser can fake the Origin header, so what really protects your users is the session token, together with rate limits.

Secret keyComing soon

A secret key is for calls from your servers only. Never put it in an app or a web page. Send it as Authorization: Bearer sb_sk_live_….

  • Shipbell shows it once and keeps only its SHA-256 hash, so copy it into your server's secrets right away.
  • It always expires. The default is one year, and the admin warns you 14 days before.
  • Shipbell records when it was last used.
  • It has explicit scopes, listed below.

Secret key scopesComing soon

ScopeAllows
posts:readListing and reading posts, with their diagnostics and short-lived attachment links
posts:writeChanging posts (status, title, tags, visibility, merges and links), creating fix cards and roadmap items, commenting, and posting reports and ideas on a user's behalf
votes:writeVoting on a user's behalf
users:readExporting a user's data
users:writeCreating and updating users
users:deleteErasing a user
changelog:writePublishing changelog entries
webhooks:writeManaging webhook endpoints

Create keysComing soon

You create keys in the project's settings in the admin. Creating a key asks you to confirm your sign-in again if it is more than 10 minutes old.

Find leaked keys

Every key starts with a fixed prefix and ends with a checksum, so a leaked key is easy to find and cheap to reject. In secret scanners, redaction rules and log searches, match the full prefixes sb_pk_live_, sb_sk_live_ and sb_ses_, never sb_ alone. Supabase keys start with sb_publishable_ and sb_secret_, so a rule written for one never catches the other.