Environments and API keys

Development versus production, the two key types, and how to rotate them.

Two environments

Every project has development and production. They share agents, tools, components and triggers as configuration, but each has:

  • its own published agent versions,
  • its own API keys,
  • its own end users, conversations and events,
  • its own numbers on the Overview page (switch with the pill in the top bar).

Rules and notifications are evaluated per environment, so nothing you test in development reaches production users.

Two kinds of keys

KeyPrefixWhere it livesWhat it can do
Publishablekl_pub_live_… / kl_pub_dev_…Shipped inside the appOpen sessions only. Cannot read other users’ data or change configuration.
Secretkl_sec_live_… / kl_sec_dev_…Your servers, CI, dashboardsSend notifications to users, read agents, call management endpoints. Never ship it in an app.

Keys are shown once when created and stored hashed. Create a new key, roll it out, then revoke the old one; several keys can be active at the same time.

Where to set them

  • Flutter: KletsoConfig(publishableKey: …). Use a --dart-define or flavour to switch between the development and production keys.
  • Server: Authorization: Bearer kl_sec_… on POST /v1/notifications and the other secret-key endpoints.
  • Dashboard: API keys page, per environment.

Last updated 2026-09-28 · Report an issue with this page