Developer Platform
API Keys
Create, scope and rotate API keys securely
API keys authenticate programmatic requests to the Developer Platform. Each key is scoped, revocable, and tied to your developer account.
Create a key
- •Dashboard → Developer Platform → API Keys.
- •Click Create key, give it a name (e.g.
ci-release-bot) and select scopes. - •Copy the key once — it's shown only at creation.
export THEAIMART_API_KEY="tm_live_9f2c...redacted"
Scopes
Grant the minimum a key needs:
| Scope | Grants |
|---|---|
listings:read | Read apps, web apps, agents |
listings:write | Create/update listings |
releases:write | Publish releases & rollouts |
webhooks:manage | Manage webhook subscriptions |
analytics:read | Read metrics |
finance:read | Read revenue & payouts |
Rotate without downtime
Keys are long‑lived, so rotate them on a schedule:
- •Create a new key with the same scopes.
- •Deploy it to your environment/secrets manager.
- •Confirm traffic is using the new key.
- •Revoke the old key.
# Revoke a compromised or retired key
curl -X DELETE https://api.theaimart.co/api/v1/api-keys/$KEY_ID \
-H "Authorization: Bearer $THEAIMART_API_KEY"
If a key leaks, revoke it immediately — revocation takes effect at once. Then audit recent activity in the key's usage log.
Handling keys safely
- •Store in environment variables or a secrets manager, never in code or client bundles.
- •Use separate keys per environment (dev/staging/prod) and per system (CI, backend, scripts).
- •Prefer test keys (
tm_test_…) in non‑production; they can't affect live listings or payouts.