> ## Documentation Index
> Fetch the complete documentation index at: https://docs.metastreams.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an API key

> How to request a key, how evaluation and production keys differ, and how to rotate or revoke one.

Every request to `/v1` needs an API key. Keys are issued by our team; there is no self-serve signup.

## Request a key

Ask for a key at `{{KEY_REQUEST_URL}}`. Tell us:

* Your company and a contact email.
* What you are building.
* Whether you want an evaluation key or a production key.

## What you receive

A key is `chr_live_` followed by 43 characters.

The first 17 characters, such as `chr_live_9tK2vQx7`, are the key's **prefix**. The prefix identifies the key without revealing it. Quote the prefix, never the full key, when you contact support.

## Evaluation and production keys

An evaluation key and a production key see the same data and meet the same [limits](/concepts/rate-limits). The only difference is that an evaluation key has a fixed expiry date, agreed when we issue it.

After that date, new requests and new stream connections with the key return `401 UNAUTHORIZED`. Streams already open with the key stay open until they close.

## Keep your key secret

* Store the key in a secret manager or an environment variable on your server.
* Never put the key in browser code, a mobile app, a public repository or a URL. See [Keys belong on your backend](/get-started/authentication#keys-belong-on-your-backend) for why.
* Use one key per environment, so you can revoke one without touching the others.

## Rotate a key

1. Ask for a new key.
2. Deploy the new key everywhere the old one runs.
3. Restart your stream connections, so none still runs on the old key.
4. Ask us to revoke the old key.

Both keys work until the old one is revoked, so the rotation needs no downtime.

## Revoke a leaked key

If a key leaks, contact us at `{{KEY_REQUEST_URL}}` with its prefix. Within about 30 seconds of revocation, new requests and new stream connections with the key return `401 UNAUTHORIZED`, like any unknown key.

<Warning>
  Revocation does not close a stream connection that is already open with the key. That connection keeps receiving market data until it closes.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.