# Keys and limits

API keys, the two environments, what a key may and may never do, and the limits you can put on each one.

Every request carries one API key in the `Authorization` header. You create keys in your dashboard, under **Developers**, and you decide there exactly what each one may do.

```curl
curl https://api.phoenixperpsfunding.com/v1/me \
  -H "Authorization: Bearer $PHOENIXPERPS_API_KEY"
```

`GET /v1/me` answers with what the key you are calling with may do: its environment, access, accounts, limits and rate budget. Call it first when something is refused and you are not sure why.

## Two environments

A key belongs to one environment for life, and its prefix says which:

| Prefix | Host | Reaches |
|---|---|---|
| `ppk_live_` | `api.phoenixperpsfunding.com` | Your evaluation and funded accounts |
| `ppk_test_` | `sandbox-api.phoenixperpsfunding.com` | Your sandbox accounts |

You can hold up to 5 active keys in each environment. A key used on the other host is refused with `401 wrong_environment`, and the message names the right host.

## Read, or read and trade

**Read** keys see accounts, risk, positions, orders, fills, history and market data. **Read and trade** keys can also place, change and cancel orders, close positions and run server-side strategies. Give a dashboard or a journal a read key: it then cannot trade, whatever happens to it.

## Limits you can set on a key

Each key can carry its own guard rails. They are checked before an order reaches the engine, and they hold even if your code has a bug.

- **Accounts**: all your accounts in the environment, or only the ones you pick. A key limited to one account does not follow it when that account is reset or funded.
- **Markets**: only the markets you list.
- **Reduce-only**: the key can close and shrink positions, never open or grow them.
- **Max order** and **max position**, in dollars of notional.
- **Daily loss stop**: when the account loses this much in the day, the key flattens the account, cancels its orders and stops trading on it until midnight New York.
- **IP allowlist**: up to 10 addresses or ranges. A request from anywhere else is refused with `403 ip_not_allowed`.
- **Rate budget**: a lower request rate than the default, for a key you hand to something you trust less.

> [!WARNING]
> The daily loss stop flattens the whole account, including positions and orders you opened from Odin or Quantower, and the dashboard says so before you save it.

## Expiry and rotation

Live keys expire after 90 days unless you pick another length, up to 365 days. A live key that never expires needs an IP allowlist. We email you 7 days before a key expires. Sandbox keys never expire unless you choose a date.

Creating a live key takes a code we email you, valid 10 minutes. Sandbox keys need none.

## What a key can never do

Whatever its access, a key cannot withdraw money or ask for a payout, change your password or email, read your trading platform login, or create keys, TradingView links or webhook endpoints. Those stay in your dashboard, behind your password.

## Keeping keys safe

- Keep the key in an environment variable or a secret store, never in your code or a repository.
- Never put a key in a web page or a mobile app: anyone could read it there.
- One key per bot or tool. When one is exposed, revoke it in the dashboard; it stops working at once, and nothing else is affected.
- Never share a key with another person or service. Letting someone else trade your account breaks the API terms.

## When a key is refused

| Code | Status | Meaning |
|---|---|---|
| `missing_api_key` | 401 | No `Authorization` header |
| `invalid_api_key` | 401 | Unknown or mistyped key |
| `expired_api_key` | 401 | The key passed its expiry date |
| `revoked_api_key` | 401 | The key was revoked |
| `wrong_environment` | 401 | A live key on the sandbox host, or the reverse |
| `ip_not_allowed` | 403 | The request came from outside the allowlist |
| `insufficient_permission` | 403 | A read key tried to trade |

Every code is in the [error catalogue](/reference/errors).
