Send signals with a customer API key
When your agent runs inside a customer’s own infrastructure, it still has to
send signals to Paid, but that environment should never hold your organization
API key. A customer API key is bound to one customer, and the only thing it can
do is send that customer’s signals through
POST /api/v2/signals/bulk.
Prerequisites
- An organization API key with the
write:api-keysscope. Full-access keys have it. - The customer, created in Paid. You address it by its Paid ID (
cus_...) or by your own external ID. - Customer API keys turned on for your organization. Ask your Paid contact to
enable them; until then, creating one returns
403FEATURE_NOT_ENABLED.
Create a customer API key
Create the key from your own backend with your organization key, or from the API keys tab on the customer’s page in the dashboard.
The secret is in key, prefixed paid_ck_live_, or paid_ck_test_ in a
sandbox organization. Paid returns it only this once and keeps just its hash,
so put it straight into the customer environment’s secret store. Pass an
optional expiresAt to limit its life; without one, the key works until you
revoke it.
Send signals
Use the customer key as the bearer token, exactly as you would an organization
key. Every signal must name the key’s customer, by customerId or
externalCustomerId.
Node.js
Python
Go
What the key can and cannot do
Idempotency keys sent with a customer key are scoped to that customer: before
checking for duplicates, Paid prefixes them with the reserved paid:ck:
prefix and an identifier for the customer. The same idempotencyKey from two
different customers’ keys, or from your organization key, is not a duplicate
of the other. Keep the paid:ck: prefix out of the idempotency keys your
organization key sends, as those could match a customer key’s.
Revoke a key
Revoke a key with
DELETE /api/v2/customers/{id}/api-keys/{apiKeyId},
its external ID twin, or the customer’s API keys tab. It stops working
within a minute. Keys are never deleted: a revoked key stays in the list with
revokedAt set, and deleting a customer revokes its keys too.