Skip to content
Thyme Docs

Gate API keys

Gate uses RPC service keys associated with a workspace and project. They differ from Flow management keys and Lift's lift_sk_… integration secrets.

Create and use a key

Open API Keys → New key, select a project, and provide a label without spaces. The workspace must have an active subscription for the RPC service. Owners and admins can create and revoke keys; members can view project keys and endpoint information.

A key becomes usable after provisioning completes. Select it on Endpoints to obtain network URLs with that key embedded. Creating a key for one project does not grant access to another workspace's management resources.

The console lists key name, a shortened key representation, creation date, requests in the last 24 hours, and last-use time. Use separate keys for environments or applications so traffic and revocation are easier to identify.

Rotate without interrupting traffic

Gate rotation uses a replacement key:

  1. Create a new key in the same intended project.
  2. Copy the new endpoint URL for each network your application uses.
  3. Update the server's secrets and deploy the configuration.
  4. Make a read request and confirm traffic on the replacement key.
  5. Revoke the old key after its consumers have switched.

The key label can identify its purpose, but it is not an access-control rule.

Revoke a key

Use the key's action menu and choose Revoke key. Revocation is permanent once completed. The backend coordinates revocation with the serving gateway and records status; if that operation fails, it can remain in a revocation state while retries run. Check the resulting status instead of assuming a failed revocation request completed.

Revoking a Gate key affects future requests using it. It cannot undo a transaction already broadcast to the chain. Cancelling the RPC subscription also revokes that product's keys.

Protect endpoint URLs

The complete execution URL contains the key. Store it in server secret configuration, redact it from HTTP logs and traces, and avoid including it in issue reports or screenshots.

An endpoint placed in a browser bundle or public configuration is visible to users of that application. Do not treat it as a server secret or assume origin restrictions are configured. Use a server-side request path where a key must remain private.

Use the apikey header for chain discovery, and use the copied authenticated URL for execution calls. Do not send a Lift or Flow credential to Gate.