API keys
Agents authenticate to https://api.vulnify.io with an API key. Send it as Authorization: Bearer or as X-API-Key. Live keys start with vln_live_. Test keys start with vln_test_. The secret is not a JWT. See Authentication.
Only owners and admins manage keys. Create one in app.vulnify.io on the API keys page.
Fields
Section titled “Fields”| Field | Behavior |
|---|---|
| Name | A label for where the key is used, such as production-agents. |
| Environment | LIVE or TEST. |
| Expires in (days) | Optional. Empty means the key does not expire on a timer. |
| Bind to an agent | Optional. A bound key can only report events for that agent. |
| Allowed source IPs | Optional, separated by commas. Empty means any IP. |
Live and test keys
Section titled “Live and test keys”TEST events are sandbox events. The SDKs report sandbox: true (Python: sandbox). The app keeps sandbox events out of dashboards and usage. A live key is the one you use when the decision should count.
Copy the secret when the app shows it. The key is stored only as a hash and cannot be shown again. Put it in VULNIFY_API_KEY on the host that runs the agent. Do not send it to the model or log it.
Bound keys
Section titled “Bound keys”If a key is bound to an agent, a check for a different agent is rejected with HTTP 403. The same status is used when the caller IP is not in the key allowlist. Fail-open does not swallow that error. The export, or whatever action you gated, does not run.
Revoking
Section titled “Revoking”Revoking a key takes effect immediately and cannot be undone. Calls with the old secret fail authentication. The audit history of past events stays.
What the SDKs send
Section titled “What the SDKs send”Both SDKs set:
Authorization: Bearer <api key>You can send the same secret as X-API-Key when you call the API without an SDK.
A missing key throws in the constructor (apiKey is required / api_key is required). A missing, invalid, revoked, or expired key returns HTTP 401. A call with no valid key has a JSON body whose message is Invalid API key. The SDKs raise on 401. They do not turn it into a fail-closed BLOCK.

