Skip to content

Getting your API key

Keys are created in the portal, not through the API. Sign in at app.prokure.ca, go to Settings → API keys, create a key, give it a name, and select the scopes it needs.

The secret starts with pk_live_ and is shown exactly once. Prokure stores only a SHA-256 hash of it, so no later request can reproduce it. The portal’s key list shows a name, the last few characters, the scopes, and when the key was last used, but never the secret. Copy it into your secret manager as you create it.

If you lose it, there is no recovery path. Revoke the key and create a replacement.

A key can also be given an expiry at creation time. An expired key is rejected the same way a revoked one is.

Scopes. A key can only do what its scopes allow, and an empty scope list grants nothing. Pick the narrowest set the integration actually needs.

One key per integration. Separate keys are cheap, and revoking one does not disturb the others.

Creating a key is a browser-session action. An API key can never mint another API key, so a leaked key cannot create successors for itself.