Miniwall Docs
Project setup

API keys and allowed origins

The public key your site or app uses, how to rotate it, and how to restrict which websites and apps may use it.

Your site or app identifies its project with a public key. The API keys page lists the keys, and an admin creates and revokes them.

Public keys

A public key starts with pk_. A new project already has one. The SDK sends it with every request:

UIKit.configure({ apiKey: 'pk_your_public_key' });

A public key can only read published screens and send view events. It is safe in your page's code or your app bundle. It is not a secret, so treat Allowed sources below as a guard against casual reuse.

Keys starting with sk_ (secret) are not created and no server API accepts them yet. Do not look for one.

A revoked key stops working at once: the API answers Missing or invalid public key. You can have several active public keys.

Rotate a key without downtime

  1. Create a new public key (admin role).
  2. Deploy your site or app with the new key in configure.
  3. Check Install SDK shows Live.
  4. Revoke the old key. Revoking cannot be undone.

Allowed sources

By default any website or app can use your public key. Allowed sources (Pro plan and above) limits that, in one list on the API keys page. Each entry has a type (Website, iOS or Android) and a value. An empty list allows everything. The first entry blocks every other site and app, so add all of them before you go live.

An entry is a guard against using the key in the wrong place by mistake. A site address or app ID can be copied, so it is not security.

Websites

Once the list has at least one website, a browser request whose Origin is not on it gets 403 with origin_not_allowed:

https://other.example is not in this project's allowed websites

Rules:

  • An entry is a scheme, a host and an optional port, with no path. example.com is stored as https://example.com.
  • Each subdomain is its own entry. https://shop.example.com, https://www.example.com and https://example.com are three entries.
  • Port and scheme count. Add http://localhost:3000 (your dev port) for local work.
  • Up to 20 websites.
  • Requests with no Origin header (server calls) are not blocked.

Apps

Apps send no Origin, so the SDK sends the app ID in an X-Miniwall-App header: ios:com.acme.app or android:com.acme.app. When the list has at least one app and the app is not on it, the API answers 403 with app_not_allowed. A request without the header passes.

Pick iOS and enter the bundle ID, or pick Android and enter the application ID (the package name). Add every build that ships with a different ID, including test builds. Up to 20 apps. See SDK installation.

Errors you may see

ErrorCause
Missing or invalid public keyThe key is wrong, has a typo, or was revoked.
403 origin_not_allowedThe site is not a Website in Allowed sources.
403 app_not_allowedThe app ID is not an iOS or Android entry in Allowed sources.

More: Errors and Security and CSP.

On this page