Crawler log keys
Create, rotate and revoke the secret crawler log key that authenticates AI crawler log uploads, and see how it differs from an API token.
A crawler log key (pik_…) lets a server upload log lines for one
site, for the AI crawlers report. That is
its only job. Unlike the public site id, it's a secret: anyone with it
can upload log lines for your site.
You only need one if you send your own logs. The tracking script and the Cloudflare sync don't use it.
Create or rotate#
Site settings → Tracking → Crawler log key → Create key. The key is shown once. Copy it into your secret store (environment variable, secrets manager). We only keep a SHA-256 digest and a short prefix so you can recognize it.
Once a site has a key, the button reads Rotate key. Rotating creates a
new key: it works immediately and the old one stops working. To rotate
without a gap, deploy the new key right after creating it. Log uploads
sent with the old key in between get 401.
Revoke removes the key, and log uploads are rejected until you create a new one. A site has at most one key.
Both need the sites.manage permission. They are also
API operations and MCP tools (tracking_ingest_key_rotate and
tracking_ingest_key_revoke), so you can rotate keys from your
infrastructure tooling. The API shows the key's prefix as
ingest_key_prefix. Over MCP the two tools only return a link to the
Tracking tab, see Actions for a person.
Keep it secret#
- Never put a crawler log key in browser code or public repositories. The tracking script needs only the public site id.
- Store it in an environment variable, e.g.
PRIVATUS_INGEST_KEY, the name the examples on the site's AI crawlers page use.
Crawler log keys vs API tokens#
Crawler log key pik_… |
API token pat_… |
|
|---|---|---|
| Scope | One site | A member's workspace access, narrowed by permissions and sites |
| Can | Upload crawler log lines | Read stats, manage settings, everything in the API |
| Used at | POST /api/logs (AI crawler logs) |
Every .json endpoint and /mcp |
An API token can't upload log lines and a crawler log key can't read data.