SiftDocs
Developer

API Keys

API keys let you authenticate programmatic requests to the Sift REST API. Each key is scoped to your organization.

At a glance

Generate keys in Settings → API & Developer✅
Pass in the X-API-Key header✅
Scoped to your organization✅
Revoke any key, effective immediately✅
Default scope on every keyread only
Grant write scope from the UI❌ not available today
Retrieve a key after creation❌ shown only once

Generating a Key

  1. Go to Settings → API & Developer (/app/settings/api-keys).
  2. Click New API Key.
  3. Copy the key immediately - it will not be shown again.

Using Your Key

Pass the key in the X-API-Key header on every request:

GET https://api.getsift.ai/v0/action/list
X-API-Key: sk_live_your_key_here

Scopes

Every key generated today is created with read-only access. There's no way to grant write scope from Settings - the only write-gated route on the API, setting an action's custom fields, isn't reachable with a key created through the UI. If you need write access, talk to your Sift contact.

Revoking a Key

You can revoke any key at any time from the same API & Developer settings page. Revocation is immediate - any in-flight requests using that key will fail.

Best Practices

  • One key per integration. Don't share a single key across multiple systems. If one integration is compromised, you can revoke only that key without disrupting others.
  • Rotate regularly. Generate a new key, update your integration, then revoke the old one.
  • Never commit keys to source control. Store them in environment variables or a secrets manager.

Treat API keys like passwords - never paste them into chat, logs, or public repositories.

On this page