Environments and API keys
Development versus production, the two key types, and how to rotate them.
Two environments
Every project has development and production. They share agents, tools, components and triggers as configuration, but each has:
- its own published agent versions,
- its own API keys,
- its own end users, conversations and events,
- its own numbers on the Overview page (switch with the pill in the top bar).
Rules and notifications are evaluated per environment, so nothing you test in development reaches production users.
Two kinds of keys
| Key | Prefix | Where it lives | What it can do |
|---|---|---|---|
| Publishable | kl_pub_live_… / kl_pub_dev_… | Shipped inside the app | Open sessions only. Cannot read other users’ data or change configuration. |
| Secret | kl_sec_live_… / kl_sec_dev_… | Your servers, CI, dashboards | Send notifications to users, read agents, call management endpoints. Never ship it in an app. |
Keys are shown once when created and stored hashed. Create a new key, roll it out, then revoke the old one; several keys can be active at the same time.
Where to set them
- Flutter:
KletsoConfig(publishableKey: …). Use a--dart-defineor flavour to switch between the development and production keys. - Server:
Authorization: Bearer kl_sec_…onPOST /v1/notificationsand the other secret-key endpoints. - Dashboard: API keys page, per environment.