Hermoddocs

Authentication

How api keys work, where to put them, and how to rotate or revoke them.

Every authenticated request carries the same secret: your api key. Where you put it in the request is up to you.

Key format

Keys are issued with a originrpc_live_ prefix followed by a random suffix. The full string is what we check; the prefix is informational.

originrpc_live_abc123def456ghi789jklmnopqrstu

Older keys minted before the rename use the os_live_ prefix. Both work, but new keys are always issued with originrpc_live_.

Treat a key like a password: anyone holding it spends your quota. The dashboard can show the full key again at any time (it is stored encrypted), so there is no need to paste it into chat or tickets. If a key leaks, revoke it and mint a new one.

Three ways to send the key

The gateway accepts any of these. URL path takes precedence if a key appears in both places.

Drop-in compatible with Alchemy-style URLs.

https://infra.originstake.com/<chain>/<arch>/<KEY>
curl https://infra.originstake.com/pharos/evm/originrpc_live_YOUR_KEY \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"eth_blockNumber","params":[]}'

Trade-off: the key appears in any access log that captures full URLs. Fine for client-side prototypes; for server traffic prefer the header form.

Anonymous access

Hitting the bare endpoint with no key is allowed and falls into our anonymous tier:

curl https://infra.originstake.com/pharos/evm \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"eth_blockNumber","params":[]}'

Anonymous traffic is rate-limited per IP and is intended for try-before-signup. See rate limits for the exact caps. Production traffic should always use a key.

Managing keys

All key management lives in the dashboard at endpoint.originstake.com/dashboard/keys.

Mint a key

Click New key, give it a name, and confirm. The dashboard shows the full secret; copy it into your secret manager. You can reveal it again later from the keys page.

Rotate a key

Click the Rotate icon in the key row and choose when the old key stops working: immediately, in 1 hour, in 24 hours, or in 7 days.

  1. A new key is created with the same name, app, chain and origin restrictions as the old one.
  2. Deploy the new key to your application.
  3. The old key keeps working until the time you picked (shown as retires in … in the table), then is revoked automatically within a minute.

The Last used column tells you when traffic has moved off the old key; you can also revoke it early with Revoke.

Revoke a key

Click Revoke in the key row. Revocation takes effect within seconds. A revoked key returns 401 Unauthorized.

Soft-revoked keys stay in the table for audit. To hard-delete a revoked key, use the trash icon next to its row.

Tying keys to apps

Each key can be scoped to one app in the dashboard. This is purely for organizing usage and billing: an app groups keys, gets its own usage graphs, and can have a custom display name. Keys still authenticate independently of which app they belong to.

See /dashboard/apps to create or rename apps.

On this page