Authentication
Learn how to authenticate with urvo using API keys
urvo uses API keys to authenticate requests. Your API keys carry many privileges, so be sure to keep them secure! Do not share your secret API keys in publicly accessible areas such as GitHub, client-side code, and so forth.
API Keys
All API requests must be authenticated using an API key. Include your API key in the Authorization header of your HTTP requests:
Authorization: Bearer YOUR_API_KEYExample Request
Here's how to make an authenticated request to the urvo API:
curl -X GET "https://api.urvo.io/v1/agents" \
-H "Authorization: Bearer sk-urvo-1234567890abcdef" \
-H "Content-Type: application/json"API Key Types
Secret Keys
Secret keys are used for server-to-server communication and have full access to your account.
- Start with
sk-urvo- - Full read/write access
- Should be kept secure on your server
- Never expose in client-side code
Publishable Keys
Publishable keys are used for client-side applications and have limited permissions.
- Start with
pk-urvo- - Read-only access to public data
- Safe to use in client-side applications
- Cannot modify sensitive data
Security Best Practices
- Rotate keys regularly: Update your API keys every 90 days
- Use environment variables: Store keys in environment variables, not in code
- Restrict key permissions: Use the minimum permissions necessary
- Monitor key usage: Check your dashboard regularly for unusual activity
- Revoke compromised keys: Immediately revoke any keys that may be compromised
Error Responses
If authentication fails, you'll receive a 401 Unauthorized response:
{
"error": {
"type": "authentication_error",
"message": "Invalid API key provided",
"code": "invalid_api_key"
}
}Rate Limiting
API requests are rate limited based on your plan:
| Plan | Rate Limit | Burst Limit |
|---|---|---|
| Free | 100 requests/hour | 10 requests/minute |
| Pro | 1,000 requests/hour | 50 requests/minute |
| Enterprise | Custom | Custom |
When you exceed the rate limit, you'll receive a 429 Too Many Requests response.