> **Building with AI coding agents?** Install the authstack plugin with one command. This equips your agent with accurate Scalekit implementation patterns.
>
> **Recommended**:
> ```bash
> npx @scalekit-inc/cli setup
> ```
>
> Global:
> ```bash
> npm install -g @scalekit-inc/cli
> scalekit setup
> ```
>
> Supports Claude Code, Cursor, GitHub Copilot, Codex + skills for other Agent Skills-compatible agents.
> Skills: integrate-agentkit, implement-saaskit, add-mcp-oauth, implement-sso, implement-scim.
> [Full setup guide](https://docs.scalekit.com/dev-kit/build-with-ai/)

---

# API credentials

Find your AgentKit environment URL, client ID and client secret in the Scalekit dashboard, load them as environment variables, and rotate a secret safely.
Your code authenticates to Scalekit with three values: the environment URL, a client ID and a client secret. This page shows where to find them, how to load them, and how to rotate a secret without downtime.

## Before you start

- A Scalekit account. Signing up creates a Development environment. See [Environments and regions](/agentkit/environments/).
- The **Admin** or **Developer** role. Members can't see API credentials. See [Team members and roles](/agentkit/team-members/).

## Get your credentials

Each environment has its own credentials. Check that the environment switcher at the top left shows the environment you want, then:

1. Open **Developers** > **Settings** > **API Credentials**.

2. Copy the **Environment URL** and the **Client ID** from **Environment details**.

3. Under **Client secrets**, select **Generate new secret**, then **Copy to clipboard**.

   The secret is shown once. Scalekit stores only a hash of it, so if you lose it, generate a new one. New environments start with no secret.

## Load them in your code

The SDKs read these environment variables. Keep them in a `.env` file that you don't commit, or in your platform's secret manager:

```bash title=".env"
SCALEKIT_ENVIRONMENT_URL=https://<name>.scalekit.dev
SCALEKIT_CLIENT_ID=<client-id>
SCALEKIT_CLIENT_SECRET=<client-secret>
```

**Python**

```python
import os
from scalekit import ScalekitClient

scalekit_client = ScalekitClient(
    env_url=os.environ["SCALEKIT_ENVIRONMENT_URL"],
    client_id=os.environ["SCALEKIT_CLIENT_ID"],
    client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
)
actions = scalekit_client.actions
```

**Node.js**

```ts
import { ScalekitClient } from '@scalekit-sdk/node';

const scalekit = new ScalekitClient(
  process.env.SCALEKIT_ENVIRONMENT_URL!,
  process.env.SCALEKIT_CLIENT_ID!,
  process.env.SCALEKIT_CLIENT_SECRET!,
);
```

**cURL**

```bash
TOKEN=$(curl -sS "$SCALEKIT_ENVIRONMENT_URL/oauth/token" \
  -d grant_type=client_credentials \
  -d client_id="$SCALEKIT_CLIENT_ID" \
  -d client_secret="$SCALEKIT_CLIENT_SECRET" | jq -r .access_token)
```

Use these credentials only on your server. Never put the client secret in browser or mobile code, where anyone can read it.

## Rotate a client secret

An environment can have two secrets at a time, so you can switch to a new one before the old one stops working:

1. In **Developers** > **Settings** > **API Credentials**, select **Generate new secret** and copy it.

2. Deploy the new secret to every service that uses the old one.

3. Check that the old secret's **Last used** time stops updating.

4. Select **Delete** on the old secret and confirm. It stops working immediately.

Rotate right away if a secret may have leaked, for example after it was committed to a repository or shown in logs.

## Check it worked

Run the cURL example: it prints an access token. With an SDK, any call such as `actions.get_connected_account` succeeds instead of returning `401`. The secret's **Last used** time updates in the dashboard.

## Common problems

### `401` or `invalid_client`

The client ID, secret and environment URL don't all come from the same environment, or the secret was deleted. Copy all three again from the environment you're calling.

### **Generate new secret** is disabled

The environment already has two secrets. Delete the one you no longer use, then generate a new one.

### **Delete** is disabled

It's the environment's only secret. Generate a new one first, so your code always has a working secret.

### I can't see **API Credentials**

Your role doesn't include API credentials. Ask an Admin to give you the **Developer** role.

## Next

  - [Quickstart](/agentkit/quickstart/): Make your first tool call with these credentials.
  - [Security and compliance](/agentkit/security/): How Scalekit stores credentials, and what your app is responsible for.


---

## More Scalekit documentation

| Resource | What it contains | When to use it |
|----------|-----------------|----------------|
| [/llms.txt](/llms.txt) | Structured index with routing hints per product area | Start here — find which documentation set covers your topic before loading full content |
| [/llms-full.txt](/llms-full.txt) | Complete documentation for all Scalekit products in one file | Use when you need exhaustive context across multiple products or when the topic spans several areas |
| [sitemap-0.xml](https://docs.scalekit.com/sitemap-0.xml) | Full URL list of every documentation page | Use to discover specific page URLs you can fetch for targeted, page-level answers |
