Work in progress. Some documented features are not live yet.

Authentication

Create application-scoped secret keys and give each service the permissions it needs.

All Credit API operations require a secret key except GET /v1/openapi.json. Send the key in the Authorization header:

curl --fail-with-body "https://api.orbytelabs.com/v1/application" \
  -H "Authorization: Bearer $ORBYTE_API_KEY"

The key selects the organization and application. Requests cannot override them with an orgId or appId field. The same identity in Development and Production has separate wallets and balances.

Create a key

Select the target application in the Credit dashboard. Open Developers → API keys → Create key, give the key a name, and choose a preset. Copy the secret shown after creation. Credit does not show the full secret again.

Key management requires organization admin access or the corresponding organization permission. You cannot grant scopes that your own account cannot use.

PresetUse it for
Setup and ingestionInitial catalog setup, wallet funding, reads, checks, and tracking.
IngestionA server that only checks access and tracks usage.
Read onlyReporting on catalog, subscriptions, wallets, and deposits.

An ingestion key cannot deploy prices, read wallet records, or fund a wallet. A check returns the relevant balance under events:ingest; a separate getWallet request needs wallets:read.

Permissions

PermissionOperations
credits:readRead credits and identify the key's application.
credits:writeCreate or update credits.
features:readRead features.
features:writeCreate or update features.
wallets:readList wallets and read balances.
wallets:writeCreate wallets and set their billing periods.
deposits:readRead a wallet's top-up history.
deposits:writeDeposit credits, creating the wallet if needed.
plans:readRead plan definitions and synchronization status.
plans:writeCreate and revise plan definitions.
subscriptions:readRead a wallet's subscription.
subscriptions:writeCreate checkout or portal sessions, change plans, and schedule or undo cancellation.
events:ingestCheck affordability and track usage.

Use a setup key for catalog deployment and keep it separate from a runtime ingestion key. A payment handler that calls topup also needs deposits:write. Hosted subscription checkout and billing management need subscriptions:write; paid top-up checkout also needs subscriptions:write. Existing keys do not gain these permissions automatically.

SDK credentials

The SDK reads your API key when a request is made and connects to https://api.orbytelabs.com automatically:

ORBYTE_API_KEY=cr_secret_your_key

No API URL variable is required. The CLI loads .env.local beside orbyte.config.ts; existing process variables take precedence. In your application, load environment variables through your server runtime or framework.

You can override credentials for one call:

import { check } from "@orbytelabs/credit";

const access = await check("api-call", "customer_123", {
  apiKey: process.env.ORBYTE_API_KEY,
});

Keep keys and callback pricing on your server. Resolve wallet identities from your authenticated user or organization. Accepting an arbitrary identity from a browser would let that caller spend someone else's wallet. A secret key with events:ingest can submit the resolved amount for callback-priced features.

Rotate or revoke a key

Create a replacement key in the same application, update the relevant server environment, and verify requests with it. Then revoke the old key in Developers. Revoked keys stop working. The catalog, wallets, and ledger history remain in the application.

A missing or invalid key returns 401. A key without the operation's permission returns 403. See errors and retries for response formats.

On this page