---
title: "Set up keys and scopes for hosted data"
description: "Match credential class, fixed scopes, and Site ownership."
canonical_url: "https://gscdump.com/gscdump-sdk/guides/operate/keys-and-scopes"
last_updated: "2026-10-03T07:15:32.029Z"
---

# Set up keys and scopes for hosted data

Hosted v1 checks the credential class, required scope, and resource ownership for each operation.

## Choose a credential class

::table{tabindex="0"}
| Class        | Used by                      | Access                                    |
| ------------ | ---------------------------- | ----------------------------------------- |
| User API key | Your own server integration  | Its user and authorized Sites             |
| Partner key  | A linked partner integration | Linked users, Teams, and authorized Sites |
::

The [hosted HTTP specification](/gscdump-sdk/api/hosted-http#api-specifications) publishes each operation's `security`, `x-gscdump-scopes`, and `x-gscdump-ownership` fields.

## Create and store a user API key

### Self-service key

Generate the key in [Agent setup](/app/developers#api-keys). Copy it once and store it in a server secret store. User keys have a fixed scope set. You do not select scopes during creation.

### Partner-issued key

A partner can create a key for a linked user with `createUserApiKey`. This method requires a partner key and `users:write`; it is not a user self-service SDK call.

Send the key as `Authorization: Bearer <key>`. The SDK does this through `credential: () => key`. Never put a key in a URL, browser bundle, browser storage, WebSocket frame, or log.

## Check scope and Site ownership

::table{tabindex="0"}
| Operation            | Scope               | Resource check  |
| -------------------- | ------------------- | --------------- |
| `queryAnalyticsRows` | `analytics:execute` | Authorized Site |
| `getSiteIndexing`    | `indexing:read`     | Authorized Site |
| `inspectSiteUrls`    | `indexing:write`    | Authorized Site |
| `getSiteSitemaps`    | `sitemaps:read`     | Authorized Site |
::

An allowed scope alone does not grant a different Site. Use its exact `siteId`.

## Rotate or revoke a key

Add a new key to the server secret store, deploy it, then revoke the old key. A partner can use its partner-only key methods for keys it issued. Check active clients before revocation.

## Diagnose forbidden access

For `401`, check that the Bearer key is present and active. For `403`, check the operation's credential class, scope, Site ownership, and Site ID. Include the request ID in support reports. See [Errors and retry](/gscdump-sdk/guides/operate/errors-and-retry).

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
