Authentication
Every request to the Dokly API is authenticated with a bearer token scoped to a single project.
Updated 2 May4 min read
Issuing a key
Open Project settings → API and press New key. Keys are shown once — copy the value into your secret manager before closing the dialog.
Keep tokens server-side. Dokly keys grant write access to your published docs. Never bundle them into client code or commit them to a public repo.
Rotating keys
Treat your Dokly key like a database password — rotate on a schedule. The Rotate action issues a fresh secret and keeps the old one valid for a 24-hour grace window.