API Keys
Motomarks uses API keys to authenticate requests. You can view and manage your keys in the dashboard.
Publishable Keys
Publishable keys (starting with pk_) are designed to be used in client-side code (e.g., browsers, mobile apps). They have limited permissions and are primarily used with the Image CDN.
Secret Keys
Secret keys (starting with sk_) are for server-side use only. They have full access to your account's API capabilities and should never be exposed in client-side code or version control. They authenticate the JSON API and headless connections to the MCP server.
- Do not check your secret keys into version control (git).
- Use environment variables to store your keys.
- If you suspect a key has been compromised, roll it immediately in the dashboard.
- Use publishable keys for all frontend implementations.
- On Pro and Enterprise, restrict each publishable key to your production domains so a leaked key cannot be reused on other sites.
Pro and Enterprise accounts can attach an allowlist of hostnames to each API key. When set, the Image CDN and API edge reject requests whose Origin or Referer host is not on the list.
- Exact hosts:
app.example.com - Wildcard subdomains:
*.example.com(does not include the apex; addexample.comseparately if needed) - Empty allowlist means unrestricted. Localhost-style hosts are always permitted for local development.
- Server-side secret-key calls without an Origin/Referer are still allowed when an allowlist is set.
Manage domains from the API Keys dashboard.