API Keys
Create and manage API keys.
Risicare is in closed beta
Access is by invitation. The link in your invitation email opens the sign-in page — start there rather than from the addresses on this page. The link does not sign you in by itself: sign in with the same email address the invitation was sent to, or it is not accepted. If a step here does not work for you during the beta, write to support@risicare.ai.
API keys authenticate your application with Risicare. Each key is scoped to exactly one project — this is how the gateway knows which project your traces belong to.
Key Format
Treat an API key as an opaque string. Copy it exactly as the dashboard shows it, and do not check its format in your code.
Keys are validated by SHA256 hash -- the plaintext key is never stored. The ingest gateway caches a validated key for up to 60 seconds. The scores route checks the key on every request.
Key management is dashboard-only
Creating, listing, and revoking API keys must be done from the dashboard's OAuth-authenticated UI. No route manages keys for a request that carries an API key — you cannot manage keys with a Bearer rsk-... token. Use Settings → API Keys in the dashboard.
Creating Keys
Via Dashboard
Owners and admins can create keys; members and viewers cannot. Creating a key needs a recent sign-in — if you are asked to re-authenticate, sign in again and retry.
- Navigate to Settings → API Keys
- Click "Create API Key"
- Select the target project (if you have multiple projects)
- Enter a name (e.g., "production-sdk")
- Click "Create Key"
- Copy the key and quickstart snippet (shown only once!)
Auto-generated on project creation
When you create a new project, a default API key is generated automatically and shown once, in the Project Created dialog — copy it there. The first person to sign in to a new organization also gets a default project whose key is shown once on the dashboard home page. Create keys manually for additional access (e.g., key rotation, per-service keys), to replace a key you did not save, or when you joined an organization that already has a project — the key list shows prefixes only and cannot reveal a key again.
No API path — use the dashboard
There is no API-key-authenticated way to create a key. Create keys from Settings → API Keys in the dashboard. The full key is shown only once on creation — store it securely.
Using Keys
In SDK
import risicare
risicare.init(api_key="rsk-...")Environment Variable
export RISICARE_API_KEY="rsk-..."In API Requests
Send the key in the Authorization header: Authorization: Bearer rsk-.... During the beta an API key works over HTTP on the ingest gateway and on the scores route only — see REST API.
Key Security
Best Practices
- Never commit keys to version control
- Use environment variables or secrets managers
- Create separate keys for each environment
- Rotate keys periodically
- Revoke unused keys
Key Rotation
- Create a new key
- Update your application
- Verify new key works
- Revoke old key
A key stops working when its creator leaves
A key also stops working when the person who created it is removed from the organization, suspended or deleted — even if nobody revokes the key. Before you remove someone, replace any key they created that your applications still use.
Viewing Keys
The list of keys for your project (with prefixes and last-used timestamps) is shown on the dashboard's Settings → API Keys page. There is no Bearer-authenticated way to list keys.
Revoking Keys
Via Dashboard
- Navigate to Settings → API Keys
- Click the delete button next to the key
- Confirm with Delete
Deleting a key revokes it, and it cannot be undone. Owners and admins can revoke keys. Revoking needs a recent sign-in, like creating a key. The ingest gateway can keep accepting spans from a revoked key for up to 60 seconds, until its cached copy expires.
No API path — use the dashboard
There is no API-key-authenticated way to revoke a key. Revoke keys from the dashboard's OAuth-authenticated UI.
Rate Limits
| Surface | Default | Scope |
|---|---|---|
Ingest gateway (https://ingest.risicare.ai/v1/..., where the SDK sends spans) | Limited | Per project, and per client IP address |
A request over the gateway's own limit is refused with 429 Too Many Requests and a Retry-After header — back off and retry. A limit at the network edge can answer 429 without that header.
The Management API is not available with an API key during the beta, and no per-key limit is enforced.