Skip to main content

What is an API key?

An API key (vela_live_...) is the credential your application uses when calling POST /v1/ingest. It is scoped to a single app — it can only ingest events into that app and has no access to any management endpoints. This scope is intentional. Your API key lives in production services and is sent with every event. Even if it is compromised, the worst case is fake events being ingested — an attacker cannot read data, modify schemas, or access other apps.

Format

How API keys are created

An API key is generated automatically when you create an app. The full key is shown once — at creation time only.
The full API key is returned only at creation and during rotation. Store it in your secret manager immediately — Vela stores only a hashed version and cannot recover the original.

Using an API key

Rotating an API key

Rotate a key if it is compromised or as part of regular security hygiene. The old key is revoked instantly on rotation.
Rotation is instant and irreversible. If multiple services share an API key, update all of them. A brief window of 401 Unauthorized errors is expected between rotation and deployment.

Viewing existing apps

The full key value is not shown after creation. You can list apps and see masked hints:
If you need the full key, rotate it to receive a new one.