Skip to content

API Keys

Latch uses a two-key model: one publishable key and one secret key.

Go to Settings > API Keys and create a pair.

You receive:

  • a publishable key (pk_...) for browser-safe access checks, events, and customer auth
  • a secret key (sk_...) for server-side subscription flows

Keys are stored as separate records. Revoking a full pair means revoking both records.

CapabilityPublishable (pk_)Secret (sk_)
Check accessYesNo
Send eventsYesNo
Customer authYesYes
Lookup active subscriptionNoYes
Create checkout sessionNoYes
Create portal sessionNoYes

Dashboard-admin CRUD routes currently use authenticated admin sessions, not API keys.