API credentials

One header stands between your app and every MediaSFU endpoint

Create keys, decide where they are allowed to run, hand scoped temporary keys to partners, and rotate any of it without redeploying your product.

No key yet? Create an account — a sandbox key is waiting in your dashboard.

Choose the trust boundary

Same product access. Different origin policy.

Key type decides where a request may come from. It does not unlock or withhold features — your plan, credits and permissions still decide what can run.

Sandbox key

Works from any origin

Runs the full set of features enabled on your account from anywhere — local tools, preview builds, live apps, and the MediaSFU sandbox.

  • No domain registration needed to start
  • Powers the in-browser endpoint sandbox
  • Domain restrictions still recommended in public apps
Production key

Bound to approved domains

Identical features, tighter blast radius: browser requests are accepted only from the HTTPS domains you have registered.

  • Rejects requests from unregistered origins
  • Not used on the MediaSFU sandbox page
  • The key to ship in front of real customers
Disposable key

Temporary and scoped

Hand a partner or a short-lived job a key that expires on its own and can only call the operations you grant it.

  • Set validity in days, or never expire
  • Allow only chosen operations, e.g. createRoom
  • Issued as either a sandbox or production type

Registering domains for a production key takes a minute in the dashboard — and it is what stops a leaked key being useful anywhere else.

Lifecycle

Create, restrict, use, rotate

  1. Create

    Generate a key in the dashboard and pick its trust boundary — sandbox for building, production for live traffic.

  2. Restrict

    Register the domains a production key may be called from, and scope disposable keys to the operations they actually need.

  3. Use

    Send one header. The same credential pair authenticates rooms, recordings, SIP, translation and AI agent endpoints.

  4. Rotate

    Regenerate on a schedule, or the moment a key is exposed. Revoking a disposable key takes effect immediately.

Quickstart

Your first authenticated call

Creating a room is the entry point for everything on MediaSFU — meetings, calls and AI agents all start here.

  • One endpoint, one header, JSON in and JSON out
  • The same shape across every SDK we publish
  • Try it against your own key in the endpoint sandbox
Open the endpoint sandbox
curl -X POST https://mediasfu.com/v1/rooms \
  -H "Authorization: Bearer yourUsername:yourApiKey" \
  -H "Content-Type: application/json" \
  -d '{
    "action": "create",
    "userName": "host",
    "duration": 30,
    "capacity": 5,
    "eventType": "conference"
  }'
Keeping keys safe

Four habits worth building in early

Keep keys off the client

Never ship a key in front-end code or commit one to a repository. Read it from an environment variable or a secrets manager.

Separate your environments

Build and stage on a sandbox key, run live traffic on a production key, and never mix the two inside one application.

Rotate on a schedule

Plan a regular rotation for production keys — every 90 days is a sensible default — and regenerate immediately if one leaks.

Disable what you are not using

Keys you have stopped calling are pure exposure. Turn them off, and review domain lists and permissions periodically.

Questions

The things people ask first

The origin policy, not the feature set. A production key accepts browser requests only from the HTTPS domains you have registered; a sandbox key is not tied to registered domains. What your account can run is still decided by your plan, credits and permissions.

Ready when you are

Your keys, allowed domains and disposable keys all live in one place in the dashboard. SDKs, quickstarts and endpoint references live in the developer portal.