Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

API credentials

Find your AgentKit environment URL, client ID and client secret in the Scalekit dashboard, load them as environment variables, and rotate a secret safely.

Your code authenticates to Scalekit with three values: the environment URL, a client ID and a client secret. This page shows where to find them, how to load them, and how to rotate a secret without downtime.

Each environment has its own credentials. Check that the environment switcher at the top left shows the environment you want, then:

  1. Open Developers > Settings > API Credentials.

  2. Copy the Environment URL and the Client ID from Environment details.

  3. Under Client secrets, select Generate new secret, then Copy to clipboard.

    The secret is shown once. Scalekit stores only a hash of it, so if you lose it, generate a new one. New environments start with no secret.

The SDKs read these environment variables. Keep them in a .env file that you don’t commit, or in your platform’s secret manager:

.env
SCALEKIT_ENVIRONMENT_URL=https://<name>.scalekit.dev
SCALEKIT_CLIENT_ID=<client-id>
SCALEKIT_CLIENT_SECRET=<client-secret>
import os
from scalekit import ScalekitClient
scalekit_client = ScalekitClient(
env_url=os.environ["SCALEKIT_ENVIRONMENT_URL"],
client_id=os.environ["SCALEKIT_CLIENT_ID"],
client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
)
actions = scalekit_client.actions

Use these credentials only on your server. Never put the client secret in browser or mobile code, where anyone can read it.

An environment can have two secrets at a time, so you can switch to a new one before the old one stops working:

  1. In Developers > Settings > API Credentials, select Generate new secret and copy it.

  2. Deploy the new secret to every service that uses the old one.

  3. Check that the old secret’s Last used time stops updating.

  4. Select Delete on the old secret and confirm. It stops working immediately.

Rotate right away if a secret may have leaked, for example after it was committed to a repository or shown in logs.

Run the cURL example: it prints an access token. With an SDK, any call such as actions.get_connected_account succeeds instead of returning 401. The secret’s Last used time updates in the dashboard.

The client ID, secret and environment URL don’t all come from the same environment, or the secret was deleted. Copy all three again from the environment you’re calling.

The environment already has two secrets. Delete the one you no longer use, then generate a new one.

It’s the environment’s only secret. Generate a new one first, so your code always has a working secret.

Your role doesn’t include API credentials. Ask an Admin to give you the Developer role.