Give your app a key
Some features need a key from another service, such as Stripe, Resend or an AI provider. crisp tells you the exact name of each key it needs. Here is how to give it one safely.
Updated
A key lets your app use another service on your behalf. Only you can create it, in your account with that service. crisp never makes up a key.
Which keys crisp asks for#
| Feature | Key names | Where to get them |
|---|---|---|
| Payments | None to copy by name: connect Stripe in the Payments panel | stripe.com, Developers, API keys |
RESEND_API_KEY, and EMAIL_FROM for your own sender | resend.com, API Keys | |
| AI features | ANTHROPIC_API_KEY | console.anthropic.com, API Keys |
| Sign in with Google or GitHub | AUTH_GOOGLE_ID and AUTH_GOOGLE_SECRET, or AUTH_GITHUB_ID and AUTH_GITHUB_SECRET | Google Cloud console, or GitHub developer settings |
When a feature needs a key, crisp builds everything around it, shows a "not set up yet" message in its place, and asks for the key by its exact name in its final reply.
Keys live in Secrets, a private list for each project. Your app can read them. The AI that builds your app only ever sees their names, never the values.
Give crisp a key#
- Create the key in your account with the service, and copy it.
- When crisp asks for a key, press the Add button under its reply, for example Add RESEND_API_KEY. Or open the More menu in the top bar and choose Secrets.
- Check the Name, paste the key into Value, and press Save secret.
- Your preview restarts so the app can use the key. Try the feature in the preview.
Manage your secrets#
- You cannot see a value again after you save it. To change it, press Replace and enter the new value.
- Press Delete to remove a secret. Your app stops getting it, and your preview restarts.
- Names use capital letters, numbers and underscores, such as
RESEND_API_KEY. A few names are reserved for crisp, such asPORTandDATABASE_URL. - Your published app gets your secrets when you publish. After you change a secret, publish again so the live app uses the new value.
- Secrets are never part of your code, so they are not in your GitHub repository.
Keep your keys safe#
- Never paste a key into a page, a form field of your app, or a file in the Code tab.
- Prefer test keys while you build. Stripe test keys start with
sk_test_. - If a key leaks, delete it at the service and create a new one. Then give crisp the new key.
Related pages
Something wrong or missing on this page? Tell us. A person reads every message.
Report a problem