Skip to content

API keys

Agents authenticate to https://api.vulnify.io with an API key. Send it as Authorization: Bearer or as X-API-Key. Live keys start with vln_live_. Test keys start with vln_test_. The secret is not a JWT. See Authentication.

Only owners and admins manage keys. Create one in app.vulnify.io on the API keys page.

Field Behavior
Name A label for where the key is used, such as production-agents.
Environment LIVE or TEST.
Expires in (days) Optional. Empty means the key does not expire on a timer.
Bind to an agent Optional. A bound key can only report events for that agent.
Allowed source IPs Optional, separated by commas. Empty means any IP.

TEST events are sandbox events. The SDKs report sandbox: true (Python: sandbox). The app keeps sandbox events out of dashboards and usage. A live key is the one you use when the decision should count.

Copy the secret when the app shows it. The key is stored only as a hash and cannot be shown again. Put it in VULNIFY_API_KEY on the host that runs the agent. Do not send it to the model or log it.

If a key is bound to an agent, a check for a different agent is rejected with HTTP 403. The same status is used when the caller IP is not in the key allowlist. Fail-open does not swallow that error. The export, or whatever action you gated, does not run.

Revoking a key takes effect immediately and cannot be undone. Calls with the old secret fail authentication. The audit history of past events stays.

Both SDKs set:

Authorization: Bearer <api key>

You can send the same secret as X-API-Key when you call the API without an SDK.

A missing key throws in the constructor (apiKey is required / api_key is required). A missing, invalid, revoked, or expired key returns HTTP 401. A call with no valid key has a JSON body whose message is Invalid API key. The SDKs raise on 401. They do not turn it into a fail-closed BLOCK.