token header. There is no OAuth handshake, no bearer token exchange, and no session initialization step — possession of the key is authority, which means it must never leave your backend. This page covers the two key types, how to locate them, example requests, and security best practices.
Authentication Method
Youverify uses a singletoken header for server-to-server authentication. Pass it on every request alongside Content-Type: application/json:
Key Types
Youverify issues two types of credentials. Use the right one for the right context:Secret API Key
Full API access. Use for all server-to-server calls. Never expose this key in client-side code, mobile apps, or version control.
Public Merchant Key
Scoped only to SDK session initialization and hosted flows (e.g. liveness capture, document upload). Safe to embed in web or mobile clients.
Where to Find Your Keys
Retrieve your API keys from the Youverify dashboard:1
Sign in to the dashboard
Go to cowork.youverify.co and sign in to your workspace.
2
Open Workspace Settings
Click your workspace name or avatar in the top navigation, then select Workspace Settings.
3
Navigate to API Keys
In the settings sidebar, click API Keys. Your sandbox and production keys are listed separately.
4
Copy the correct key
Copy the key for the environment you are targeting — sandbox keys work only against
https://api.sandbox.youverify.co, and production keys work only against https://api.youverify.co.Example Request
The followingcurl example creates an entity using a secret API key in the token header:
Authentication Errors
401 Example
403 Example
Security Best Practices
Follow these practices to keep your API keys secure:1
Use environment variables
Never hard-code a secret key in source code. Load it at runtime from environment variables (
YV_SECRET_KEY) or a secrets manager such as AWS Secrets Manager, HashiCorp Vault, or GCP Secret Manager.2
Use separate keys per environment
Keep sandbox and production keys entirely separate. Treat your production key as the highest-sensitivity credential in your system.
3
Rotate keys regularly
Generate a new secret key from the dashboard periodically, update your environment variable, and revoke the old key. Rotate immediately if you suspect a key has been exposed.
4
Never commit keys to version control
Add key files and
.env files to .gitignore. Scan your repository history with tools like git-secrets or trufflehog before making it public.5
Restrict server egress where possible
If your infrastructure supports it, restrict outbound calls to the Youverify API to a specific service or network segment so the key is used only from expected origins.
The public merchant key is safe to embed in web and mobile apps because it is scoped solely to starting a liveness or document-capture session — it cannot create entities, run verifications, or access any data.