Get your API key
1
Sign up
Create an account at platform.decart.ai
2
Create an API Key
Navigate to API Keys and create a new API Key
3
Copy key
Copy your API key
Use your API key
Pass your API key when making requests:Best practices
- Store keys in environment variables
- Rotate keys regularly
- Use different keys for development and production
Realtime client-side authentication
For browser and mobile apps, use client tokens instead of your permanent key (dct_...).
Create a token from your backend:
apiKey is a signed client token the gateway verifies offline, so requests don’t wait on a key lookup. Hand it to your frontend.
Token lifetime
Client tokens expire 60 seconds after minting by default (expiresIn, 1–3600 s). Mint right before connecting, or pass apiKeyProvider to createDecartClient so the SDK fetches a fresh token for every connect and reconnect. An expired token is rejected with TOKEN_EXPIRED before any socket is opened. See Token lifetime.