API keys
Create, scope, expire and revoke keys.
API keys live under API keys in your dashboard, at
ssnap.cc/<your-team>/api-keys.
Creating a key
Give the key a name (up to 255 characters) and, optionally, an expiry date. Names are for you: use them to identify which system a key belongs to, so revoking one later is not guesswork.
The key value is displayed once, right after creation. Only a SHA-256 hash is stored, so it cannot be shown again. Copy it into your secret store immediately.
New keys are active on creation and belong to the team that was current when you made them.
What a key is scoped to
| Scope | Effect |
|---|---|
| Team | Every capture is owned by the key's team and drawn from that team's monthly quota. |
| Plan | The key's per-minute rate limit comes from the team's plan. |
| Expiry | After expires_at, requests fail with 403 api_key_expired. |
Keys are throttled individually, so several keys on one team each get the full per-minute allowance while sharing one monthly quota. See Rate limits and quotas.
Expiry
An expiry date is optional; without one the key works until deleted. Expiry is a useful default for keys handed to contractors, CI pipelines or short-lived experiments.
Revoking
Delete a key from the dashboard and it stops working immediately. Deletion is restricted to the team the key belongs to.
Screenshots captured with a deleted key are not removed; they stay in your history until retention prunes them.
Rotation
- Create a new key with a name marking the rotation (
billing-service-2026-09). - Deploy it.
- Confirm traffic on the new key.
- Delete the old one.
Since keys are throttled independently, a rotation does not halve your throughput while both are live.
If a key leaks
Delete it first, then investigate. A leaked key can spend your whole monthly allowance and every capture it makes is attributed to your team.
Never embed a key in a browser, mobile app or public repository. Put captures behind your own backend endpoint, and keep the key server-side.
Quick generate
The Screenshots page has a quick-generate form for trying parameters without writing code. It uses one of your active keys and consumes quota exactly like an API call, so test renders count against your monthly allowance.