Skip to main content
Every request is authenticated with an organization API key. Create one on the settings page of the Deutero dashboard.

Pass the key

An explicit api_key takes precedence over the environment variable. If neither is set, the constructor raises ValueError before any request is made. The key is sent in the X-API-Key header on every request, including when you bring your own HTTP client.
Treat API keys like passwords. Load them from the environment or a secrets manager rather than committing them to source control.

Authentication errors

PermissionDeniedError subclasses AuthenticationError, so catch it first if you want to handle the two differently. See Error handling.

Keys that never reach the API

Two kinds of secret are separate from your API key:
  • Webhook signing secrets (whsec_...) verify deliveries Deutero sends you. Verification runs locally and needs no API key. See Receiving webhooks.
  • Embed publishable keys let a website load the interview widget. See Recruitment and embedding.