Skip to content
Venue Authority

Venue Authority trust center

API-key handling and account isolation

API keys belong to an account and their plaintext value is shown once.

Last reviewed: 2026-08-15

Key storage

Venue Authority stores a lookup prefix and HMAC digest, not the plaintext key. The dashboard cannot retrieve or inject the one-time value into a browser request.

Account ownership

Each customer account has one private Venue Authority data boundary. Evaluation, key, billing, watchlist, webhook, and acquisition reads check account ownership.

Complimentary access

The complimentary test allowance is claimed once across the verified user, verified primary email digest, and account. Rotation replaces only the complimentary primary key and does not add credits.