ZeroLeaks API authentication
Authenticate ZeroLeaks scans with server-side API keys, and distinguish scan access from Shield access.
Create an API key in ZeroLeaks dashboard settings. Send it to https://zeroleaks.ai/api/v1 in the Authorization header:
Authorization: Bearer zl_live_...
Content-Type: application/jsonWith @zeroleaks/sdk, set ZEROLEAKS_API_KEY in the server environment and initialize new ZeroLeaks(). Never include a key in browser bundles, NEXT_PUBLIC_ variables, mobile apps, source control, or logs. Endpoint configuration reads omit target credentials; those credentials are separate from your ZeroLeaks API key.
Scan creation requires an active scan plan and access to the requested workspace. Reads are scoped to the API key owner. Public health, capabilities, OpenAPI, agent instructions, and MCP documentation resources do not require a key.
The Shield API uses https://api.zeroleaks.ai/v1 and has separate access rules: acknowledged free keys can use shield, while paid subscriptions also include the other Shield models. A free Shield key does not grant scan access.
A 401 means the key is missing, invalid, or revoked. A 403 means access or subscription requirements are unmet. Fix credentials or access before retrying. See errors and rate limits.