An API key lets your server fetch your workspace's published face lenses and screen effects from the delivery API. It is the only credential the delivery API accepts.
Owners and Developers. Designers don't see the API keys page; ask an Owner or a Developer for a key.
Keys start with mk_.
mk_
Important: The key is shown exactly once. IngevoraMirage keeps only a hash of it, so nobody can show it to you again. If you lose a key, revoke it and issue a new one.
Send the key in the X-Api-Key header of every delivery request:
X-Api-Key
GET /v1/lenses/8f3c2a10-… HTTP/1.1 Host: mirage-api.ingevora.com X-Api-Key: mk_…
One key works for both products. Whether a product answers depends on your workspace, not on the key: if screen effects are off for your workspace, every key gets a 403 for them. A missing, unknown or revoked key gets a 401. See Delivery API.
403
401
Treat a key like a password. Anyone who has it can fetch your workspace's published items.
Issue a separate key for each app and each server. Then a leak, or a server you retire, costs you one key while the others keep working. A clear name tells you which key is which.
The list shows each key's name, its first characters (for example mk_AbCdEfGh…), the date it was created, and its status: Active or Revoked. The full key is never shown again.
mk_AbCdEfGh…
Revoke a key as soon as you think it has leaked, or when you stop using it.
A revoked key can never be used again, and there is no undo.