Skip to main content
The Reflection API authenticates every request with an API key, sent in the Authorization header.

Create an API key

The Reflection platform is in beta, and access is opening gradually. New sign-ups join a waitlist and can create API keys once their access is enabled.
  1. Sign in to the Reflection platform.
  2. Open API Keys and select the project the key is for.
  3. Create the key and copy it. Its full value is shown only once, right after creation.
API keys belong to a project and to the user who created them:
  • A key can make requests only against its project. Use separate projects to keep keys and usage apart, for example one per application or environment.
  • A key is disabled if the user who created it is removed from the organization or the project.
If you can’t create a key, ask an administrator of your organization for access. Some organizations must add a verified payment method before creating keys.

Send the key

Pass the key in the Authorization header:
The examples in these docs read the key from the REFLECTION_API_KEY environment variable:

Keep keys secure

  • Treat a key like a password. Anyone who has it can make requests billed to your organization.
  • Keep keys on your server. Don’t embed them in browser or mobile apps, and don’t commit them to source control.
  • Load keys from environment variables or a secret manager.
  • Revoke a key from the API Keys page if it may have been exposed, and replace it with a new one.

Authentication errors

See Errors for the full list.