← Back to blog
AI & Automation3 min read

Create and securely manage API keys: Read, Write, Revoke

Bild von Unsplash

What an API key is

An API key is a long, random string that allows a program to identify itself to a service. Whoever knows it can do everything the key permits. Therefore, an API key must be stored securely like a password. At Same-QR, you need it for the command line sameqr, for your own scripts via the REST API, and for coding agents like Claude Code, Cursor, and Codex. ChatGPT and Claude.ai do not need one; they log in via OAuth.

Step 1: Find the right location

Log in to the dashboard and open Account. There you will find the section “Access for CLI, scripts and agents”. Keys can only be created here, with a browser login. A key cannot generate further keys, so a stolen key does not multiply.

Step 2: Choose permissions

There are three levels. Always choose the smallest one that is sufficient for the task.

  • Scan reports, evaluations, an assistant that only answers questions: read only.
  • Scripts that create codes and pages, change names and texts, publish, read maps: read + write.
  • Processes that change the goals of existing codes, take pages offline, or delete them: full. Each such change requires confirmation with the read state; via the API, at most 10 per hour and 30 per day.

With a read-only key, every changing request is rejected. A coding agent connected via MCP with a read-only key does not see the write tools at all.

Step 3: Validity period and name

Every key expires: after 30, 90, 180, or 365 days; 90 days is the default. Unlimited is also possible, but you must choose it consciously, for example for a nightly task without humans to renew it. Give the key a name according to its purpose, e.g., “Monthly Report Customer A”. Up to 10 keys are possible per account.

Step 4: Save securely immediately

The key starts with sqr_live_ and is displayed exactly once. Same-QR only stores a checksum and cannot show it to you later. Store it directly in your password manager. Programs read it from the environment variable SAMEQR_API_KEY at startup. A key must not be:

  • in the source code, especially not in a public repository,
  • in an address, because addresses end up in logs and histories,
  • in a table, email, or chat message,
  • in the chat with an AI assistant,
  • as an argument in a command, because then it appears in the shell history.

The fixed prefix sqr_live_ serves a purpose: tools that search for accidentally published secrets recognize the key by this prefix.

Step 5: Revoke if necessary

In the same list, you revoke a key with one click. It becomes invalid immediately, while your codes remain unchanged. Expired keys remain in the list with a note so you can see why a script suddenly stops working. Changing your password revokes all keys at once. Revoke a key if it has become visible anywhere, if a service provider no longer works for you, or if you no longer know what it is for.

Conclusion: why Same-QR

Same-QR takes keys seriously: separate permissions, lifetimes with sensible defaults, displayed only once, stored only as a checksum, and revocation with immediate effect. This allows you to use API, CLI, and coding agents calmly, in any plan.

Get started right away: sign up for free at sameqr.com, two dynamic QR codes are free forever. API, CLI and MCP server are included in every plan, and the documentation is at sameqr.com/entwickler.

Create dynamic QR codes for free
Start with 2 dynamic QR codes that are free forever. No subscription, no credit card.
Start free now →

Frequently asked questions

Can I view a key again later?

No. It is only displayed when created; only a checksum is stored. If it is lost, revoke it and create a new one.

Do I need a key for ChatGPT or Claude.ai?

No. There you add Same-QR as a connector and log in via OAuth. A key is required for the CLI, custom scripts, and coding agents.

What happens to my QR codes if I revoke a key?

Nothing. The codes remain unchanged and scannable. Only the program with that key will no longer have access.

Reserve a spot

Reserve your spot before we go live.

One email as soon as the tool goes live — including pricing and the free plan. No spam, unsubscribe any time.

Only until launchLaunching in the next few weeks
  • Your free account is reserved — there is nothing to pay yet anyway
  • 90 days of unlimited destination changes instead of 30, only for early sign-ups
  • Launch price locked in, even if we raise prices later

By subscribing you consent to receiving the newsletter. You can withdraw consent at any time via the unsubscribe link in every email.

Keep reading