Docs
Navegar pela documentação

Crawler log keys

Create, rotate and revoke the secret crawler log key that authenticates AI crawler log uploads, and see how it differs from an API token.

Ver como Markdown

A crawler log key (pik_…) lets a server upload log lines for one site, for the AI crawlers report. That is its only job. Unlike the public site id, it's a secret: anyone with it can upload log lines for your site.

You only need one if you send your own logs. The tracking script and the Cloudflare sync don't use it.

Create or rotate#

Site settings → Tracking → Crawler log key → Create key. The key is shown once. Copy it into your secret store (environment variable, secrets manager). We only keep a SHA-256 digest and a short prefix so you can recognize it.

Once a site has a key, the button reads Rotate key. Rotating creates a new key: it works immediately and the old one stops working. To rotate without a gap, deploy the new key right after creating it. Log uploads sent with the old key in between get 401.

Revoke removes the key, and log uploads are rejected until you create a new one. A site has at most one key.

Both need the sites.manage permission. They are also API operations and MCP tools (tracking_ingest_key_rotate and tracking_ingest_key_revoke), so you can rotate keys from your infrastructure tooling. The API shows the key's prefix as ingest_key_prefix. Over MCP the two tools only return a link to the Tracking tab, see Actions for a person.

Keep it secret#

  • Never put a crawler log key in browser code or public repositories. The tracking script needs only the public site id.
  • Store it in an environment variable, e.g. PRIVATUS_INGEST_KEY, the name the examples on the site's AI crawlers page use.

Crawler log keys vs API tokens#

Crawler log key pik_… API token pat_…
Scope One site A member's workspace access, narrowed by permissions and sites
Can Upload crawler log lines Read stats, manage settings, everything in the API
Used at POST /api/logs (AI crawler logs) Every .json endpoint and /mcp

An API token can't upload log lines and a crawler log key can't read data.