Authorization header.
Create an API key
The Reflection platform is in beta, and access is opening gradually. New sign-ups join a waitlist and can create API keys once their access is enabled.
- Sign in to the Reflection platform.
- Open API Keys and select the project the key is for.
- Create the key and copy it. Its full value is shown only once, right after creation.
- A key can make requests only against its project. Use separate projects to keep keys and usage apart, for example one per application or environment.
- A key is disabled if the user who created it is removed from the organization or the project.
Send the key
Pass the key in theAuthorization header:
REFLECTION_API_KEY environment variable:
Keep keys secure
- Treat a key like a password. Anyone who has it can make requests billed to your organization.
- Keep keys on your server. Don’t embed them in browser or mobile apps, and don’t commit them to source control.
- Load keys from environment variables or a secret manager.
- Revoke a key from the API Keys page if it may have been exposed, and replace it with a new one.
Authentication errors
See Errors for the full list.