Developer
API Keys
API keys let you authenticate programmatic requests to the Sift REST API. Each key is scoped to your organization.
At a glance
| Generate keys in Settings → API & Developer | ✅ |
Pass in the X-API-Key header | ✅ |
| Scoped to your organization | ✅ |
| Revoke any key, effective immediately | ✅ |
| Default scope on every key | read only |
Grant write scope from the UI | ❌ not available today |
| Retrieve a key after creation | ❌ shown only once |
Generating a Key
- Go to Settings → API & Developer (
/app/settings/api-keys). - Click New API Key.
- Copy the key immediately - it will not be shown again.
Using Your Key
Pass the key in the X-API-Key header on every request:
GET https://api.getsift.ai/v0/action/list
X-API-Key: sk_live_your_key_hereScopes
Every key generated today is created with read-only access. There's no way to grant write scope from Settings - the only write-gated route on the API, setting an action's custom fields, isn't reachable with a key created through the UI. If you need write access, talk to your Sift contact.
Revoking a Key
You can revoke any key at any time from the same API & Developer settings page. Revocation is immediate - any in-flight requests using that key will fail.
Best Practices
- One key per integration. Don't share a single key across multiple systems. If one integration is compromised, you can revoke only that key without disrupting others.
- Rotate regularly. Generate a new key, update your integration, then revoke the old one.
- Never commit keys to source control. Store them in environment variables or a secrets manager.
Treat API keys like passwords - never paste them into chat, logs, or public repositories.