Documentation

API keys

Long-lived rl_sk_ keys for server-side dispatch without wallet popups.

Create a key

Console → Keys → Create. The secret is shown once; store it in your secrets manager.

Use on runs
curl -X POST "https://runlayer-y9kc.onrender.com/v1/runs" \
  -H "Authorization: Bearer rl_sk_live_…" \
  -H "Content-Type: application/json" \
  -d '{"agent_id":"quick-ask","input":{"message":"Hello"}}'

Security practices

  • Never embed keys in front-end bundles or mobile apps.
  • Rotate keys from the console; revoke compromised keys immediately.
  • Scope environments (staging vs prod) with separate workspaces or keys.
  • Log receipt_id per request for audit trails.

JWT vs API key

Wallet JWTs are short-lived session tokens for the console. API keys are preferred for cron jobs, backends, and CI pipelines.