Key storage
Venue Authority stores a lookup prefix and HMAC digest, not the plaintext key. The dashboard cannot retrieve or inject the one-time value into a browser request.
Venue Authority trust center
API keys are workspace-owned credentials whose plaintext value is shown once.
Venue Authority stores a lookup prefix and HMAC digest, not the plaintext key. The dashboard cannot retrieve or inject the one-time value into a browser request.
Members of one Clerk organization share one canonical Venue Authority workspace. A personal session uses a separate personal workspace. Evaluation, key, billing, watchlist, webhook, and acquisition reads check workspace ownership.
The complimentary test allowance is claimed once across the verified user, verified primary email digest, and canonical workspace. Rotation replaces only the complimentary primary key and does not add credits.