Skip to main content
Nexor uses a different key type for each developer surface. Choose the narrowest key that supports the integration.
Never place an nxr_live_ or nxr_mcp_ key in HTML, browser JavaScript, a mobile application, a screenshot, a log, or a public repository. An nxr_pub_ key is browser-visible and is not a secret; use it only for supported Web Chat flows.

Create a REST API key

Create one key for each integration so you can revoke it without interrupting the others:
  1. In Nexor, open Settings → API Keys from the account menu at the bottom of the sidebar.
  2. Select New key.
  3. Enter a name that identifies the integration.
  4. Select Create key.
  5. Copy the key and store it securely.
Creating a key does not revoke any existing keys.

Use a REST key

Send the key in the X-API-Key header on every direct API request:
REST keys do not carry per-operation scopes. They can call the customer-facing public operations for the account, so create a separate key for each backend integration and store it in that server’s secret manager.

Use an MCP key

MCP keys start with nxr_mcp_. Create one under Settings → MCP Server, select only the scopes the MCP client needs, and store the resulting key in that client’s secret configuration. The MCP server enforces the scopes selected for the key. Public API operations that declare a route-level required scope check enforce it again and return 403 Forbidden when the key lacks that scope. See Connect the Nexor MCP Server for client configuration and the current scope list.

Use a publishable Web Chat key

Publishable keys start with nxr_pub_. The Web Chat installation screen supplies the workspace key and lets you configure allowed domains. This key is browser-visible, is not a secret, and is intended for Web Chat. The optional SDK v0.1.44 requestContact flow is not supported on untrusted public sites while backend hardening for contact requests is pending. Use the standard Web Chat capture flow, or create leads from a trusted server with an nxr_live_ key. See Web Chat for the hosted loader and npm installation paths.

Revoke a REST key

To stop a key from working:
  1. Open Settings → API Keys.
  2. Select Revoke beside the key.
  3. Confirm the action.
Revoking one key does not affect the others. Because authenticated key lookups are cached, a revoked key can remain accepted for up to 10 seconds during normal operation, or for up to 5 minutes if the database is unavailable. When rotating a key, create and install its replacement before you revoke the old one.

Error responses

Missing API key

Nexor returns 401 Unauthorized when no API key is provided.

Invalid API key

Nexor returns 401 Unauthorized when the key is invalid, or after a revocation has propagated and the cached key is no longer accepted.

Missing scope or wrong key type

Nexor returns 403 Forbidden when the MCP server or a scoped API operation rejects a key that lacks the required scope. A route that does not accept publishable keys can also return 403 Forbidden. Changing the prefix in a request does not change a key’s stored type or permissions.
Last modified on September 25, 2026