ZevAuth Docs
Sign up

Getting started

Keys and environments

Which key goes where, and which one must never reach a browser.

Every environment has its own keys. They are not interchangeable, and the difference matters.

Publishable keys

pk_test_… and pk_live_…

These identify your environment. They are not secret. They ship inside your JavaScript bundle and anyone can read them. That is fine, because a publishable key on its own can do almost nothing: it can start a sign-in, and that is the point.

What stops somebody using yours on a phishing site is origin locking. A publishable key is accepted only from your project’s verified domain, its subdomains, or a callback URL you registered. A copy of your key on your-app.attacker.example is refused.

// Correct. This is meant to be public.
<ZevAuthProvider publishableKey="pk_live_..." />

Secret keys

sk_test_… and sk_live_…

These act as your whole account. They read any user, create organizations and change anything. They belong on a server, in an environment variable, and nowhere else.

Session tokens

Not a key. A session token is the short-lived JWT that represents one signed-in person, and it is what your own API should accept.

The three are used in different places:

CredentialLivesAnswers
Publishable keyYour frontend bundleWhich app is this?
Secret keyYour server, in an env varIs this the developer?
Session tokenMemory, in one browserWhich person is this?

Endpoints under /v1/me take a session token and nothing else. Handing them a publishable key is refused, with an error that says so. Otherwise any holder of a public key could read anybody’s profile.

Rotating a key

You can rotate keys in the console. A rotated publishable key stops working immediately, so deploy the new one first.

Updated at, Friday, August 28, 2026