Account

API Keys

Keys are created when you need them: a secret key for server calls, and a publishable key as part of a widget installation. They are not interchangeable. One is meant to be visible in a browser, the other must never leave your server.

The two types

PublishableSecret
Formatwcx_pk_ plus 32 lowercase hexadecimal characterswcx_sk_ plus 32 lowercase hexadecimal characters
Belongs inBrowsers, mobile web, embed snippetsServers only
Origin checkRequired. Only origins allowed on its widget installation may use itNone
Safe to exposeYes, by design. It is visible in your page sourceNo. Treat it like a password
Typical useThe embed widget, and reading public agent appearance or the model list from a browserChat. The REST API from a backend, or the SDK on a server
Can send chatNo. chat.send in the SDK requires a secret keyYes

Both are managed on the API Keys(sign in required) page. A secret key is shown once, when you create or rotate it, and is stored only as a hash afterwards, so it cannot be shown again. A publishable key is created as part of an installation and stays available on it, in the embed snippet, along with the origins that installation allows.

Note

Chat is a secret-key capability, and it is enforced in two independent places. The official SDK refuses chat.send with a publishable key before any network request, and POST /v1/chat/completions refuses one on the server with 403 access_denied. The server-side refusal is the real boundary: it applies to curl, to a copied fetch snippet and to any OpenAI client, none of which run the SDK's check.

Where a publishable key still works

A publishable key is not restricted to one endpoint. It is valid on the public surfaces that read metadata or start a widget session, and refused on every chat route.

EndpointPublishableSecret
POST /v1/widget/sessionsYesNo. A secret key has no browser origin
GET /v1/agent/configYesYes
GET /v1/modelsYesYes
POST /v1/chat/completionsNoYes

The rule worth remembering is that a publishable key cannot reach the model. Reading an agent's appearance or the model list costs nothing and consumes no allowance, which is why those stay open to a key that ships in page source.

Why a public key is safe

A publishable key has to be readable, because it ships inside a page. What protects it is not secrecy but the origin check. A request carrying it must come from a browser origin registered on that widget installation. Copied onto someone else's site, it answers nothing.

Heads up

That protection does not exist for a secret key, which is not origin checked at all. A leaked secret key can be used from anywhere, by anyone, against your monthly allowance.

See Allowed Origins for what counts as a match.

Keeping the secret key secret

  • Read it from an environment variable. Never hardcode it in source, and never commit it.
  • Never prefix it for a client bundle. A name like NEXT_PUBLIC_ or VITE_ tells the bundler to inline the value into JavaScript the browser downloads.
  • Put a small endpoint of your own in front of it, so your frontend calls your server and your server calls Wicarax.
  • Keep it out of logs, error reports and support tickets. Log the key prefix if you need to identify which key was used.
server.ts
// The key stays on the server; the browser talks to your own route.
const wicarax = new Wicarax({ secretKey: process.env.WICARAX_SECRET_KEY });
Note

The official SDK refuses a secret key in a browser before making any network call, so an accidental import into client code fails loudly rather than leaking quietly.

Regenerating keys

Only an active key can be rotated. Rotation is per key: it issues a replacement of the same class and nothing else changes, so rotating the key in your web page cannot take your server integration down with it. The previous value stops working immediately and there is no overlap window, so the order of operations still matters.

  1. 1Decide where that one key is deployed, meaning your embed snippet, or your server environment and any automation.
  2. 2Rotate it on the API Keys page and copy the replacement.
  3. 3Update every place from step one, then deploy.
  4. 4Load your site and ask one question, or run one server-side call, to confirm the replacement works.
Heads up

Between rotating and deploying, anything still using the old key is refused. For a public site, rotate when you are ready to ship the change, not before.

A revoked key cannot be rotated. Create a new secret key to replace a revoked secret. If a revoked publishable key leaves its installation unable to serve, create a new installation for the same agent and update the embed snippet.

If a key is exposed

Exposed keyRiskWhat to do
PublishableLow. It only works from origins you allowedCheck the installation’s allowed origins for entries you do not recognise, then rotate that key when you are ready to update your snippet
SecretHigh. It works from anywhereRevoke it immediately, create a replacement, then review your monthly usage for consumption you cannot account for

After replacing a key, update every deployment that used the previous value. Usage totals are available on Usage and Analytics(sign in required).

Practical habits

  • One key per deployment, named after where it runs, so you know what breaks when you revoke it.
  • One installation per site, rather than one key shared across unrelated sites. Rotating then affects one place, and usage stays separable.
  • Register only origins you control, and remove staging entries when a project ends.
  • Deactivate an agent instead of deleting it when you want to stop traffic but keep the option to resume. Deleting takes its keys down permanently.
  • Rotate on a schedule you can maintain, and whenever someone with access leaves the project.

For what to do when a request is refused, see Errors.

Tip

Log the key prefix rather than the key. It is enough to identify which key a request used and is useless to anyone who reads your logs.

Disclaimer

Rotation has no overlap window: the old value stops working the moment the replacement is issued. Treat it as a deployment rather than as a settings change. A secret key is shown once and cannot be recovered, so copy it before you close the panel.