Docs home

API keys

Create and archive keys in the dashboard. Keys start with parse_. Use a separate one per environment, dev, staging, prod.

Keep secret keys server-side. Call ParseAPI from your backend, not from browser code or a public repo.

Need to call from a browser? Create a public key instead. Public keys start with parse_public_ and check the calling page against the domains you list. They are designed to be included in browser code. Same header, same responses, same limits.

fetch('https://api.parseapi.com/email/hi@example.com', {
  headers: { 'X-API-Key': 'parse_public_...' }
})

Add example.com and it covers every subdomain too. Add localhost to the list for local development. Metered calls like deep email verification work on public keys and count against your plan, so keep those server-side unless you mean it.

Shipping a native app? Create an app key and use the Swift or Kotlin SDK. App keys start with parse_app_. List your iOS bundle ID or Android package name on the key. The SDK sends it as X-App-Id on every request.

1. Install

Add the ParseAPI product to your app target. In Xcode, you can also add the repository URL through Add Package Dependencies.

Package.swift dependency
.package(url: "https://github.com/parseapi/swift", from: "1.8.0")

2. Add your key

Create an app key in Keys and allow your bundle identifier. Replace parse_app_... below. The SDK sends your bundle identifier automatically. Use your server for metered checks.

3. Make a request

Look up a country and print its name. This lookup uses your plan's request allowance.

Swift app code
import ParseAPI

func loadCountry() async throws {
    let parse = try ParseAPI("parse_app_...")
    let country = try await parse.country("US")
    print(country.name)
}

// Call from your app's async task.
// try await loadCountry()

Handle errors by code, such as invalid_api_key or not_found. A response with valid: false is a successful lookup.

Handle API errors in your app

The same request, with a handler for API errors. Transport failures still propagate.

Swift app code
import ParseAPI

func loadCountry() async throws {
    let parse = try ParseAPI("parse_app_...")
    do {
        let country = try await parse.country("US")
        print(country.name)
    } catch let error as ParseAPIError {
        print(error.code, error.status, error.requestId ?? "")
        throw error
    }
}

// Call from your app's async task.
// try await loadCountry()

App IDs match exactly, com.example.weather does not cover com.example.weather.widget. App keys cover lookups and plan deep. Metered endpoints like /carrier and /hlr answer 403 on an app key, call those from your server with a secret key.

Email and VAT behave differently: on an app key, ?deep=true returns the core result plus deep: {}, with no verification charge. Run those deep checks from your server with a secret key.

Archive a key in the dashboard to stop further use. Allow a few seconds for the change to take effect.

Questions? Email