Docs · 3 of 5 · about 4 minutes
Keys and access tokens
You hold one API key and one secret. Your server uses them to mint short-lived access tokens; your apps hold only the tokens. The secret never goes into an app build, a repository or a chat message.
Minting a token
Any LiveKit server SDK. The token carries the participant's identity, the room, the grants, and a lifetime.
# Python from livekit import api token = api.AccessToken(LIVECORE_KEY, LIVECORE_SECRET) \ .with_identity(user_id) \ .with_ttl(timedelta(hours=1)) \ .with_grants(api.VideoGrants(room_join=True, room=room_name, can_publish=is_host)) \ .to_jwt()
Every server languageGenerating tokens, on docs.livekit.io ↗ has the same call for Node, Go, Python, Ruby, Kotlin, PHP and Rust.
What your key can and cannot do
| Your own rooms | Full control: create, join, delete, manage participants. |
| Another tenant's rooms | Cannot see, join, delete or list them. Your key is scoped to your tenant at the gateway, not by convention. |
| Room names | Yours are your own. A tenant prefix is added and stripped invisibly, so you never see it and never collide with anyone. |
| Egress and ingress | Recording and stream pulling are not available yet. Tell us if your app depends on them. |
| Resource use | Capped by your tenant's quotas: maximum concurrent participants and rooms. Both are shown on your Account page. |
Keeping the secret secret
- Keep it in your server's environment, next to your database password.
- Short token lifetimes. An hour covers a live session; a day is rarely needed.
- If it leaks, write to [email protected] from your billing contact. We rotate it with you on a call: the new pair goes live while the old one still works, you move your server across, then the old one is retired. Nothing goes down.