API keys

Keys use the Bootstrapware prefix bsw_ with environment and type: bsw_test_pub_, bsw_live_pub_, bsw_test_sec_, bsw_live_sec_.

Publishable

Safe in the browser for loading published board config and (Hosted) post/vote calls. You may expose them as NEXT_PUBLIC_... if you accept that exposure model.

  • Live publishable config requires an active BYO ($9.99) or Hosted ($19.99) entitlement.
  • Live Hosted writes require Hosted ($19.99).
  • Test publishable keys work without a paid plan.

Secret

Server-only. Used as Authorization: Bearer for board create/draft/publish, usage, and MCP secret fallback. Never put secrets in NEXT_PUBLIC_ env vars or client bundles. Cookie sessions for the dashboard are not API keys.

Prefer OAuth Connect for Cursor when possible so mcp.json stays URL-only. See AGENTS.md.

Mint and revoke

Dashboard-only under Feedback → Keys. Not available via MCP or a secret management API. Revoke Cursor OAuth grants on the Keys page when a machine should lose access.

Trust boundary

A leaked publishable key plus forged author.id is a real risk. Mitigate with allowed origins, keep embeds behind your auth, and enable requireAuthorToken with a secret-minted authorToken when you need stronger Hosted write integrity. Details: Identity.

Related: Environments · API overview · AGENTS.md · Origins · Security