Skip to main content

Get your API key

1

Sign up

Create an account at platform.decart.ai
2

Create an API Key

Navigate to API Keys and create a new API Key
3

Copy key

Copy your API key

Use your API key

Pass your API key when making requests:

Best practices

Never hardcode API keys in your code. Use environment variables.
  • Store keys in environment variables
  • Rotate keys regularly
  • Use different keys for development and production

Realtime client-side authentication

For browser and mobile apps, use client tokens instead of your permanent key (dct_...).
Do not expose permanent API keys in frontend bundles. Always mint short-lived client tokens from your backend.
Create a token from your backend:
The response’s apiKey is a signed client token the gateway verifies offline, so requests don’t wait on a key lookup. Hand it to your frontend.

Token lifetime

Client tokens expire 60 seconds after minting by default (expiresIn, 1–3600 s). Mint right before connecting, or pass apiKeyProvider to createDecartClient so the SDK fetches a fresh token for every connect and reconnect. An expired token is rejected with TOKEN_EXPIRED before any socket is opened. See Token lifetime.
See Client Tokens for the complete backend-to-frontend flow and token rotation strategy.

Need help?