Skip to content

Security and privacy

Keys

Publishable keys go in your app; secret keys stay on your servers. Both are per environment.

KeyLooks likeWhere it goesWhat it can do
Publishableps_pub_prod_…Your app, in plain sightRead published guides; send guide events
Secretps_sec_prod_…Your servers and CI secretsPublish guides and delete user data, via the server API
  • Each environment (development, production) has its own pair.
  • Secret keys are shown once. We store only a SHA-256 hash and the first characters, for display.
  • Rotate both keys of an environment in Settings › API keys. The old publishable key stops loading guides within a minute; the old secret key stops at once.

A publishable key cannot read drafts, other environments, analytics or anything about your users.

Search the docs and guides.

PlayStep is coming soon

We're opening PlayStep to teams one at a time. Leave your name and email and we'll set up a demo.

We use your email only to arrange the demo. See the privacy policy.