Access, events & logs
API keys
Keys come in two flavors — sk_ secret keys for your backend, pk_ publishable keys for
embedding checkout widgets — and are scoped to product areas (Treasury, Pay, Trade, Earn,
Borrow) so an invoicing integration never holds trading access. Rotate or revoke a key any
time; every request it made stays in the logs.
OAuth clients
For third-party apps that act on behalf of your users rather than holding a standing key. Users approve access on a consent screen (hosted in Treasury), and you can revoke a client org-wide at any point.
Webhooks and WebSockets
Both deliver the same platform events — invoice.paid, an order approved, a trade filled:
- Webhooks push events to an HTTPS endpoint you host; delivery history (with response codes) is visible in Logs, and event types are organized in groups you subscribe to.
- WebSockets stream the same events over a live connection — for dashboards and tools that want push without running a public receiver.
The full event catalogue lives in the events reference.
RPC
Platform-operated RPC endpoints for every supported chain, with health and latency shown on the RPC page — your team doesn't need its own node provider. Endpoints are shared platform infrastructure (there are no per-org custom endpoints).
Logs
Every API request against your organization and every webhook delivery, in one place — who called what, with which key, and what came back. Combined with Treasury's audit log, machine access is as auditable as human access.