Getting your API key
Keys are created in the portal, not through the API. Sign in at app.prokure.ca, go to Settings → API keys, create a key, give it a name, and select the scopes it needs.
The secret starts with pk_live_ and is shown exactly once. Prokure stores
only a SHA-256 hash of it, so no later request can reproduce it. The portal’s
key list shows a name, the last few characters, the scopes, and when the key was
last used, but never the secret. Copy it into your secret manager as you create
it.
If you lose it, there is no recovery path. Revoke the key and create a replacement.
A key can also be given an expiry at creation time. An expired key is rejected the same way a revoked one is.
Two things worth deciding up front
Section titled “Two things worth deciding up front”Scopes. A key can only do what its scopes allow, and an empty scope list grants nothing. Pick the narrowest set the integration actually needs.
One key per integration. Separate keys are cheap, and revoking one does not disturb the others.
Creating a key is a browser-session action. An API key can never mint another API key, so a leaked key cannot create successors for itself.
Related
Section titled “Related”- Authentication & API keys: the full key lifecycle.
- Scopes explained.
- Making your first request.