Skip to documentation
DocumentationDelivery and reference

API keys and OTA Publish IDs

Choose the correct credential for management, automation, and runtime translation delivery.

On this page

Two credentials, two purposes

CredentialUseWhere it belongs
API keyAuthenticated management and CLI synchronization under the account permissions.Server environment, local untracked .env, or CI secret store.
OTA Publish IDRead-only SDK requests for a project published translation content.The SDK runtime configuration for the intended project.

The CLI authenticates management requests with X-API-Key. SDK translation delivery uses X-OTA-Publish-Id. These credentials are not interchangeable. Keep custom management integrations on a trusted server.

Create and use an API key

Open the API key area in your account and create the credential needed for your workflow. Copy it into the local environment or CI secret store. The CLI reads RERUNE_API_KEY; do not place the secret in a public frontend environment variable.

When replacing a management key, update the systems that use it and verify their requests before removing the old credential. If a request is forbidden, check the account permissions as well as the credential.

Generate an OTA Publish ID

Open the project OTA Publish IDs settings and generate an ID. You can set an expiration time. Copy the generated value when shown; the plaintext value is displayed only at creation. Put it in the matching SDK configuration.

Terminal · create an ID for the configured project

rerune project ota-id create

The CLI command prints the new value once and does not write it to rerune.json. It requires an authenticated account and a project target. Use command-specific help for an explicit project or expiration.

Expiration and rotation

When an OTA ID expires or is deleted, clients using it cannot rely on future successful fetches. Previously cached data can remain available according to SDK behavior. Plan rotation around how your apps receive configuration updates.

Generate a replacement, update the intended clients, and verify delivery. Remove the old ID only when you are ready to stop future requests from clients that still use it. Deleting an ID does not update the value embedded in an installed app.