Platform
API Keys Management
Cortiqa authenticates API requests using secret API keys generated in your developer dashboard. Every key is prefixed with sk-cortiqa- and should be kept confidential.
Generating API Keys
- Sign in to your Cortiqa account at platform.cortiqa.co.
- In the sidebar, navigate to API Keys.
- Click Create New Secret Key, provide an optional descriptive label (e.g. “Production Cluster US-East”), and copy your generated token immediately.
Save Your Secret Key
For security reasons, full API keys are only displayed once upon creation. If you lose a key, you must generate a new one and delete the old one.
Authenticating Requests
Pass your secret key in the Authorization header using the standard Bearer scheme:
Authorization: Bearer sk-cortiqa-your-secret-api-key-here
Or export it to your shell environment so all official SDKs discover it automatically:
export CORTIQA_API_KEY=sk-cortiqa-your-secret-api-key-here
Zero-Downtime Key Rotation
When rotating credentials in production without service interruptions:
- Step 1: Create a secondary key in platform.cortiqa.co.
- Step 2: Update your environment variables or secret manager (e.g., AWS Secrets Manager, HashiCorp Vault) to use the new key.
- Step 3: Redeploy or restart your application workers.
- Step 4: Check request logs in the console to verify all traffic uses the new key, then delete the retired key.
Security Best Practices
- Never commit keys to Git: Add
.env and .env.local to your .gitignore. - Do not call from browser frontend: Always route requests through your own backend server or edge function so users cannot inspect client network requests to extract your secret key.
- Isolate environments: Create separate keys for Local Development, Staging, and Production.