Authentication

Every request authenticates with an API key passed as gRPC metadata.

Keys

Keys are scoped to an environment (for example prod or staging) and a signal set (traces, metrics, logs). Create and revoke them under Settings → API keys.

Sending the key

metadata := map[string]string{"x-api-key": os.Getenv("LINKSCOPE_API_KEY")}

With the Collector, set it under headers on the OTLP exporter as shown in the quickstart.

Rotation

Create a new key, roll it out, then revoke the old one. Keys take effect within seconds and require no redeploy of the ingest endpoint.

Treat keys like passwords. A leaked key can write telemetry to your account until revoked; it grants no read access to your data.