API keys and rate limits

Updated 2026-09-08

  • Secret keys have full access. Public keys can only create links and are safe in a browser.
  • Scope a key to a single domain or team to limit its blast radius.
  • The limit is 50 requests per second per key. Use bulk endpoints for large jobs.
  • A 429 response includes Retry-After. Respect it rather than retrying immediately.

Find this in your dashboard

  1. Sign in and select the workspace and domain you want to manage.
  2. Open API keys. Review the article’s steps and your plan’s available controls.
  3. Save your changes, reopen the record and verify the saved result. For routing changes, check the short link with a test visit.
ShortFreeURL API keys in a demonstration workspace
API keys · Demo workspace. Click to enlarge.

API workflow guides · Open dashboard

Was this helpful?

Start Free — no credit card

The free plan includes 1,000 links, 6 custom domains and 50,000 tracked clicks a month, free forever. Choose a free subdomain from six shared domains. Paid plans start at $4 a month when you outgrow it, and you keep everything you have built.