Get started
API keys and environments
Keep application authentication scoped to a project and separate from dashboard sessions.
Authenticate server requests
HTTP header
Authorization: Bearer rr_test_your_secretCreate keys in the project's API Keys screen. The secret is shown once and stored as a hash. Keep it out of browser bundles, source control and logs. Revoke a compromised key and create a replacement.
Test and live environments
| Key | Project | Behavior |
|---|---|---|
rr_test_ | Development | Processes locally as simulated; no SES send or external webhook. |
rr_live_ | Production | Sends through SES after operator activation and readiness checks. |
Test and live usage have separate ledgers. Both modes require an exact verified project domain with DKIM and MAIL FROM ready. New workspaces start with production sending disabled.
Project scope and access
An API key can only access its project. Send-only keys can read messages created by that key; an email:read key can read its project's messages. Dashboard sessions manage domains, keys and webhooks separately and cannot submit email sends.