Security and privacy
Keys
Publishable keys go in your app; secret keys stay on your servers. Both are per environment.
| Key | Looks like | Where it goes | What it can do |
|---|---|---|---|
| Publishable | ps_pub_prod_… | Your app, in plain sight | Read published guides; send guide events |
| Secret | ps_sec_prod_… | Your servers and CI secrets | Publish guides and delete user data, via the server API |
- Each environment (development, production) has its own pair.
- Secret keys are shown once. We store only a SHA-256 hash and the first characters, for display.
- Rotate both keys of an environment in Settings › API keys. The old publishable key stops loading guides within a minute; the old secret key stops at once.
A publishable key cannot read drafts, other environments, analytics or anything about your users.