# Create a key

1. Open the board, then **Settings → Developer**.
2. **Create key.** Name it after what will use it — "Lead vendor", "Nightly sync".
3. Choose its scopes — only what it needs:
   - **Read** (`read`) — the board's shape and rows.
   - **Add rows** (`rows:write`) — add records. It never reads back what is already there.
4. Copy the key. **It is shown once**; Specter keeps only a fingerprint.

The dialog also shows ready-to-run `curl` commands with your key and one of the board's columns
filled in, and a **Test key** button that reads the board through it.

```bash
export SPECTER_KEY='sbk_…'
```

Send it on every request, in either header:

```http
Authorization: Bearer $SPECTER_KEY
X-API-Key: $SPECTER_KEY
```

## Keep it safe

<Callout type="danger" title="Server-side only">
  Never put a key in a browser, a mobile app or source control. For a form on a web page, use a
  [Specter form](/forms/overview) instead.
</Callout>

- Keep keys in environment variables or a secret manager.
- One key per integration, so revoking one never stops another.
- Each key's calls and failures are under **View logs** in Settings → Developer.

## Rotate or revoke

To rotate: create a new key with the same scopes, move the integration to it, check **View logs**,
then revoke the old one. **Revoke** stops a key immediately; it answers `401` from then on.
