Skip to main content
Doclo Cloud uses API keys for authentication. This guide covers key management, security best practices, and error handling.

API Key Format

Doclo API keys follow this format: Example: dc_live_org123_abcdefghijklmnopqrstuvwxyz123456

Getting API Keys

  1. Log in to app.doclo.ai
  2. Navigate to Settings → API Keys
  3. Click Create API Key
  4. Name your key (e.g., “Production Server”, “Development”)
  5. Copy and securely store the key
API keys are shown only once. If you lose a key, you’ll need to create a new one.

Using API Keys

With the SDK

With REST API

Include the key in the Authorization header:

Test vs Production Keys

Test Keys (dc_test_)

  • Safe for development and testing
  • Can connect to localhost and private IPs
  • No billing charges
  • Rate limits may be lower

Production Keys (dc_live_)

  • For production workloads
  • Cannot connect to localhost (SSRF protection)
  • Billing enabled
  • Full rate limits

Key Security

Never expose API keys in client-side code, public repositories, or logs.

Do

  • Store keys in environment variables
  • Use secret management services (AWS Secrets Manager, Vault, etc.)
  • Rotate keys periodically
  • Use separate keys for different environments
  • Revoke unused keys

Don’t

  • Commit keys to version control
  • Log API keys
  • Share keys between applications
  • Use production keys in development

Environment Variables

Key Rotation

Rotate keys periodically to limit exposure:
  1. Create a new API key
  2. Update your application to use the new key
  3. Deploy the update
  4. Revoke the old key
Use separate keys for each deployment (staging, production) to rotate independently.

Rate Limits

API requests are rate limited per organization: Rate limit headers are included in responses:

Handling Rate Limits

Authentication Errors

IP Allowlisting

For enhanced security, restrict API access to specific IP addresses:
  1. Go to Settings → Security in the dashboard
  2. Enable IP allowlisting
  3. Add your server IP addresses
Requests from non-allowlisted IPs will be rejected with a 403 error.

Next Steps

Cloud Quickstart

Get started with Doclo Cloud

REST API Reference

Direct API documentation