Create and securely manage API keys: Read, Write, Revoke
What an API key is
An API key is a long, random string that allows a program to identify itself to a service. Whoever knows it can do everything the key permits. Therefore, an API key must be stored securely like a password. At Same-QR, you need it for the command line sameqr, for your own scripts via the REST API, and for coding agents like Claude Code, Cursor, and Codex. ChatGPT and Claude.ai do not need one; they log in via OAuth.
Step 1: Find the right location
Log in to the dashboard and open Account. There you will find the section “Access for CLI, scripts and agents”. Keys can only be created here, with a browser login. A key cannot generate further keys, so a stolen key does not multiply.
Step 2: Choose permissions
There are three levels. Always choose the smallest one that is sufficient for the task.
- Scan reports, evaluations, an assistant that only answers questions: read only.
- Scripts that create codes and pages, change names and texts, publish, read maps: read + write.
- Processes that change the goals of existing codes, take pages offline, or delete them: full. Each such change requires confirmation with the read state; via the API, at most 10 per hour and 30 per day.
With a read-only key, every changing request is rejected. A coding agent connected via MCP with a read-only key does not see the write tools at all.
Step 3: Validity period and name
Every key expires: after 30, 90, 180, or 365 days; 90 days is the default. Unlimited is also possible, but you must choose it consciously, for example for a nightly task without humans to renew it. Give the key a name according to its purpose, e.g., “Monthly Report Customer A”. Up to 10 keys are possible per account.
Step 4: Save securely immediately
The key starts with sqr_live_ and is displayed exactly once. Same-QR only stores a checksum and cannot show it to you later. Store it directly in your password manager. Programs read it from the environment variable SAMEQR_API_KEY at startup. A key must not be:
- in the source code, especially not in a public repository,
- in an address, because addresses end up in logs and histories,
- in a table, email, or chat message,
- in the chat with an AI assistant,
- as an argument in a command, because then it appears in the shell history.
The fixed prefix sqr_live_ serves a purpose: tools that search for accidentally published secrets recognize the key by this prefix.
Step 5: Revoke if necessary
In the same list, you revoke a key with one click. It becomes invalid immediately, while your codes remain unchanged. Expired keys remain in the list with a note so you can see why a script suddenly stops working. Changing your password revokes all keys at once. Revoke a key if it has become visible anywhere, if a service provider no longer works for you, or if you no longer know what it is for.
Conclusion: why Same-QR
Same-QR takes keys seriously: separate permissions, lifetimes with sensible defaults, displayed only once, stored only as a checksum, and revocation with immediate effect. This allows you to use API, CLI, and coding agents calmly, in any plan.
Get started right away: sign up for free at sameqr.com, two dynamic QR codes are free forever. API, CLI and MCP server are included in every plan, and the documentation is at sameqr.com/entwickler.
Frequently asked questions
No. It is only displayed when created; only a checksum is stored. If it is lost, revoke it and create a new one.
No. There you add Same-QR as a connector and log in via OAuth. A key is required for the CLI, custom scripts, and coding agents.
Nothing. The codes remain unchanged and scannable. Only the program with that key will no longer have access.
Reserve your spot before we go live.
One email as soon as the tool goes live — including pricing and the free plan. No spam, unsubscribe any time.
- Your free account is reserved — there is nothing to pay yet anyway
- 90 days of unlimited destination changes instead of 30, only for early sign-ups
- Launch price locked in, even if we raise prices later
By subscribing you consent to receiving the newsletter. You can withdraw consent at any time via the unsubscribe link in every email.