Server-side events and log import need an API key. Browser collection does not: it carries the public site ID in its payload, see Collect (browser).
Create a key
In the console, open the API keys page in your project settings, create a key and choose its scopes. Keys start with wck_ and the full value is shown only once, when you create it. Store it in your secret manager right away.
Collection keys are bound to one project. Events go to that project, so requests do not carry a project ID.
Send the key
Use either header:
http
Authorization: Bearer wck_xxxxxxxxxxxxxxxxhttp
X-Api-Key: wck_xxxxxxxxxxxxxxxxNever put the key in a query string, front-end code or a mobile app bundle.
Scopes
| Scope | Allows | Notes |
|---|---|---|
track:write | Server behavior events | Orders, sign-ins, profile updates and other business events |
events:write | Bot access records | Access records pushed from a gateway; only requests identified as bots are kept |
logs:write | Log import | Import access logs in combined format |
Follow least privilege and create one key per use — an order service only needs track:write. A missing scope returns 403, see Errors.
Keeping keys safe
- Use keys only on the server and inject them through environment variables or a secret manager.
- Rotate regularly: create and deploy a new key, confirm traffic has moved, then revoke the old one.
- If a key may have leaked, revoke it in the console immediately. Requests with a revoked key return
401. - Never paste a full key into logs, tickets or chat. The first few characters are enough for troubleshooting.