Skip to content
msMarketSDK

// guide

Authentication

Every request carries one API key. The key alone decides which marketplace you reach, and whether it is test or live.

Two kinds of key

Kinds of API key
kindstartsuse it fromcan call
secretmsk_test_sk_ / msk_live_sk_your server onlyeverything
publishablemsk_test_pk_ / msk_live_pk_your web pagespublished listings, search, and public seller profiles
  • A secret key sent from a browser is refused with secret_key_in_browser, so a key pasted into front-end code fails at once instead of leaking quietly. Roll any key that reached a browser.
  • A publishable key calling anything else gets 403 publishable_key_not_allowed. The API reference marks the endpoints it may call.
  • List the origins your pages run on under marketplace, such as https://shop.example.com. A publishable key used from any other origin gets 403 origin_not_allowed. With no origins listed, any origin may use it.

Test keys and live keys

msk_test_ keys reach your test marketplace and msk_live_ keys your live one. They are separate marketplaces: an id from one is not found in the other, and nothing you do in test reaches live. See test and live.

Rotate and revoke

  • Name each key after where it runs, so the dashboard's last used time tells you which system still uses it.
  • Rotate makes a new key with the same name and kind. The old one can keep working for up to 7 days while you deploy the new one, or stop at once.
  • Revoke stops a key at once. Do this for a key that leaked.
  • Keys are prefixed so secret scanners can spot them. If one turns up in a repository, revoke it.

next: errors