Create a REST API key
Create one key for each integration so you can revoke it without interrupting the others:- In Nexor, open Settings → API Keys from the account menu at the bottom of the sidebar.
- Select New key.
- Enter a name that identifies the integration.
- Select Create key.
- Copy the key and store it securely.
Use a REST key
Send the key in theX-API-Key header on every direct API request:
Use an MCP key
MCP keys start withnxr_mcp_. Create one under Settings → MCP Server, select only the scopes the MCP client needs, and store the resulting key in that client’s secret configuration.
The MCP server enforces the scopes selected for the key. Public API operations that declare a route-level required scope check enforce it again and return 403 Forbidden when the key lacks that scope. See Connect the Nexor MCP Server for client configuration and the current scope list.
Use a publishable Web Chat key
Publishable keys start withnxr_pub_. The Web Chat installation screen supplies the workspace key and lets you configure allowed domains. This key is browser-visible, is not a secret, and is intended for Web Chat.
The optional SDK v0.1.44 requestContact flow is not supported on untrusted public sites while backend hardening for contact requests is pending. Use the standard Web Chat capture flow, or create leads from a trusted server with an nxr_live_ key.
See Web Chat for the hosted loader and npm installation paths.
Revoke a REST key
To stop a key from working:- Open Settings → API Keys.
- Select Revoke beside the key.
- Confirm the action.
Error responses
Missing API key
Nexor returns401 Unauthorized when no API key is provided.
Invalid API key
Nexor returns401 Unauthorized when the key is invalid, or after a revocation has propagated and the cached key is no longer accepted.
Missing scope or wrong key type
Nexor returns403 Forbidden when the MCP server or a scoped API operation rejects a key that lacks the required scope. A route that does not accept publishable keys can also return 403 Forbidden. Changing the prefix in a request does not change a key’s stored type or permissions.