Authentication and project scope
Browser and mobile collection
Use a COLLECT key for embedded SDKs. It is bound to its project and has a restricted collection scope, such as events:write. Send it as Authorization: Bearer KEY. Do not add X-Project-Id to override the project associated with a key. Never embed a SERVER key in browser or mobile code.
Server-side management
Use a SERVER key for management scripts and backend integrations. Keep it in a secret store or server environment. The operation must be enabled for keys and its required scopes must be present. Feature entitlements also apply.
| Action | Required key scopes |
|---|---|
| Read links | links:read |
| Create or update links | links:write |
| Delete links | links:write, links:delete |
| Read analytics | analytics:read |
| Ingest or identify | events:write |
A JWT session can access user-authorized operations. For JWT project operations, supply X-Project-Id: PROJECT_ID. A project identifier alone grants no access.
Errors
401 means authentication failed or expired. 403 means an authenticated caller lacks access, a required scope or feature. Inspect the response code; do not replace errors with zero-valued analytics.
Prefer test keys for manual experiments. Do not put credentials in query strings, screenshots, browser persistent storage or public repositories. The application Playground accepts test keys only and keeps them in memory.