Authentication
All public API requests are authenticated with an API key passed as a Bearer token. JWT sessions are only used by the dashboard, never by the public API.
Bearer authentication
Pass your secret key in the Authorization header on every request:
bash
Authorization: Bearer carrier_sk_live_xxxxxxxxxxxxKey types
Every API key is a matched pair, generated together and shown once. Each has a distinct prefix so you can tell them apart at a glance:
- Secret key —
carrier_sk_live_…(orcarrier_sk_test_…in development). Grants full access. Use it only server-side and never expose it in client applications. - Publishable key —
carrier_pk_live_…. Safe to embed in client-side apps where only public identification is required.
Which key can call what
Only secret keys may call protected endpoints (chat, sessions, files, search, usage). Publishable keys are for public identification only and cannot perform privileged actions.
Treat secret keys like passwords. If a key leaks, revoke it immediately from the API keys page and issue a new one — revocation is instant and permanent.
Unauthenticated requests
A missing, malformed, revoked, or inactive key returns 401. See Error Codes for the full list.
The Carrier OS CLI uses this same secret key — run
cos login once and it is stored securely on your machine (never a login token).