Guides
API keys
Each project has a publishable key for your apps and secret keys for your servers.
Two kinds of key
| Kind | Starts with | Where it goes | How Shipbell keeps it |
|---|---|---|---|
| Publishable | sb_pk_live_ | Your web and iOS apps | In plain text, so the admin can show it again |
| Secret | sb_sk_live_ | Your servers only | As a SHA-256 hash. It is shown once |
After the prefix, every key has 22 random letters and digits and a 6-character checksum.
Publishable keyComing soon
The publishable key identifies your project. Send it in the X-Project-Key header. It allows:
- reading your project's configuration,
- trading a sign-in token for a session,
- opening the board from your app,
- public reads, but only when your board is public or unlisted. On a private board, every read needs a session.
Requests from browsers are checked against your project's allowed origins. Apps outside a browser can fake the Origin header, so what really protects your users is the session token, together with rate limits.
Secret keyComing soon
A secret key is for calls from your servers only. Never put it in an app or a web page. Send it as Authorization: Bearer sb_sk_live_….
- Shipbell shows it once and keeps only its SHA-256 hash, so copy it into your server's secrets right away.
- It always expires. The default is one year, and the admin warns you 14 days before.
- Shipbell records when it was last used.
- It has explicit scopes, listed below.
Secret key scopesComing soon
| Scope | Allows |
|---|---|
posts:read | Listing and reading posts, with their diagnostics and short-lived attachment links |
posts:write | Changing posts (status, title, tags, visibility, merges and links), creating fix cards and roadmap items, commenting, and posting reports and ideas on a user's behalf |
votes:write | Voting on a user's behalf |
users:read | Exporting a user's data |
users:write | Creating and updating users |
users:delete | Erasing a user |
changelog:write | Publishing changelog entries |
webhooks:write | Managing webhook endpoints |
Create keysComing soon
You create keys in the project's settings in the admin. Creating a key asks you to confirm your sign-in again if it is more than 10 minutes old.
Find leaked keys
Every key starts with a fixed prefix and ends with a checksum, so a leaked key is easy to find and cheap to reject. In secret scanners, redaction rules and log searches, match the full prefixes sb_pk_live_, sb_sk_live_ and sb_ses_, never sb_ alone. Supabase keys start with sb_publishable_ and sb_secret_, so a rule written for one never catches the other.