# Crawler log keys

> Create, rotate and revoke the secret crawler log key that authenticates AI crawler log uploads, and see how it differs from an API token.

A crawler log key (`pik_…`) lets a server upload log lines for **one
site**, for the [AI crawlers](/docs/features/ai-crawlers) report. That is
its only job. Unlike the public site id, it's a **secret**: anyone with it
can upload log lines for your site.

You only need one if you
[send your own logs](/docs/features/ai-crawlers#connect-your-logs). The
tracking script and the Cloudflare sync don't use it.

## Create or rotate

**Site settings → Tracking → Crawler log key → Create key.** The key is
shown **once**. Copy it into your secret store (environment variable,
secrets manager). We only keep a SHA-256 digest and a short prefix so you
can recognize it.

Once a site has a key, the button reads **Rotate key**. Rotating creates a
new key: it works immediately and the old one stops working. To rotate
without a gap, deploy the new key right after creating it. Log uploads
sent with the old key in between get `401`.

**Revoke** removes the key, and log uploads are rejected until you create
a new one. A site has at most one key.

Both need the `sites.manage` permission. They are also
[API operations](/docs/api) and MCP tools (`tracking_ingest_key_rotate` and
`tracking_ingest_key_revoke`), so you can rotate keys from your
infrastructure tooling. The API shows the key's prefix as
`ingest_key_prefix`. Over MCP the two tools only return a link to the
Tracking tab, see [Actions for a person](/docs/mcp#actions-for-a-person).

## Keep it secret

- Never put a crawler log key in browser code or public repositories.
  The tracking script needs only the public site id.
- Store it in an environment variable, e.g. `PRIVATUS_INGEST_KEY`, the
  name the examples on the site's **AI crawlers** page use.

## Crawler log keys vs API tokens

| | Crawler log key `pik_…` | API token `pat_…` |
|---|---|---|
| Scope | One site | A member's workspace access, narrowed by permissions and sites |
| Can | Upload crawler log lines | Read stats, manage settings, everything in the [API](/docs/api) |
| Used at | `POST /api/logs` ([AI crawler logs](/docs/features/ai-crawlers#connect-your-logs)) | Every `.json` endpoint and `/mcp` |

An API token can't upload log lines and a crawler log key can't read data.
