Skip to main content
A Zelinqa key is a server secret. Treat it like a production password.

Backend only

Never place a key in browser JavaScript, a mobile application, or a URL.

Least privilege

A runtime key does not need to read or publish configuration.

One key per environment

Separate development, staging, production, and automation.

Immediate revocation

Revoke every lost or exposed key before creating a replacement.
  • an environment variable injected at deployment;
  • your cloud provider’s secret manager;
  • never Git, screenshots, tickets, or logs;
  • redact Authorization headers from observability.

Rotate without interruption

  1. create a second key with the same minimal scopes;
  2. deploy it to your backend;
  3. verify API calls;
  4. revoke the old key.
If a key appears in Git history, removing it from the latest commit is not enough: revoke it immediately.