API keys
What this lets you do
Authenticate server-side requests and keep credentials out of client applications.What you need
- A DreamLayer account at
platform.dreamlayer.io - Access to a server-side environment or secret manager
Steps
1. Create and store the key
Create the key in the developer console. The full secret is shown once. Enter it without writing it to shell history:2. Revoke a key
Revocation is immediate for new requests. Existing durable execution state remains available only according to the authenticated account contract. Each beta tester must use an individual key. Shared keys prevent safe attribution and revocation.Confirm it worked
An authenticated capabilities request succeeds. After revocation, the same key receives401 on a new request.
Common errors
- A lost full secret cannot be displayed again. Revoke it and create a new key.
- A key on an account with no available credit receives
402before execution.
Troubleshooting
Check that the key is present only in the server process. Keys created before 2026-08-20 carry adlr_test_ prefix and still work; new keys are always dlr_live_.