Platform

API Keys Management

Cortiqa authenticates API requests using secret API keys generated in your developer dashboard. Every key is prefixed with sk-cortiqa- and should be kept confidential.


Generating API Keys

  1. Sign in to your Cortiqa account at platform.cortiqa.co.
  2. In the sidebar, navigate to API Keys.
  3. Click Create New Secret Key, provide an optional descriptive label (e.g. “Production Cluster US-East”), and copy your generated token immediately.
Save Your Secret Key
For security reasons, full API keys are only displayed once upon creation. If you lose a key, you must generate a new one and delete the old one.

Authenticating Requests

Pass your secret key in the Authorization header using the standard Bearer scheme:

HTTP Header
Authorization: Bearer sk-cortiqa-your-secret-api-key-here

Or export it to your shell environment so all official SDKs discover it automatically:

Terminal
export CORTIQA_API_KEY=sk-cortiqa-your-secret-api-key-here

Zero-Downtime Key Rotation

When rotating credentials in production without service interruptions:

  • Step 1: Create a secondary key in platform.cortiqa.co.
  • Step 2: Update your environment variables or secret manager (e.g., AWS Secrets Manager, HashiCorp Vault) to use the new key.
  • Step 3: Redeploy or restart your application workers.
  • Step 4: Check request logs in the console to verify all traffic uses the new key, then delete the retired key.

Security Best Practices

  • Never commit keys to Git: Add .env and .env.local to your .gitignore.
  • Do not call from browser frontend: Always route requests through your own backend server or edge function so users cannot inspect client network requests to extract your secret key.
  • Isolate environments: Create separate keys for Local Development, Staging, and Production.
Was this page helpful?