Skip to main content
Kovi authenticates every API request using a secret API key tied to your Techeval account. You include this key when you initialise the Python SDK or when you make a direct REST API call. Requests made without a valid key are rejected with a 401 Unauthorized response. Keep your key private — it carries the same authority as your account credentials.

Getting Your API Key


Using with the Python SDK

Pass your API key as the api_key argument when you create a KoviClient instance. Every subsequent SDK method call — such as schedule_interview() — automatically includes this key in the request.
You only need to initialise the client once. Create a single instance at application startup and reuse it throughout the lifetime of your process.

Using with the REST API

If you are calling the Kovi REST API directly — for example, from a language without an official SDK — pass your API key in the Authorization header using the Bearer scheme:
A full example using curl:

Keeping Your Key Secure

Never hard-code your API key in source code or commit it to version control. If your key is exposed in a public repository, anyone can use it to consume your interview credits. Treat it like a password.Use an environment variable instead:
Set the environment variable in your shell or deployment environment:
For production deployments, inject the secret through your CI/CD platform (e.g., GitHub Actions Secrets, AWS Parameter Store, or a Kubernetes Secret) rather than storing it in .env files that might be committed by accident.

Key Rotation

If you suspect your API key has been compromised, or as a routine security practice, you can regenerate it at any time:
  1. Go to Settings → API Keys in the Techeval dashboard.
  2. Click Regenerate Key.
  3. Confirm the action in the dialog.
The old key is invalidated immediately. Any SDK clients or services still using the previous key will receive 401 Unauthorized errors until you update them to use the new key. Update all integrations — your production service, CI/CD pipelines, and any local .env files — before regenerating in a live environment. For questions about key management or enterprise SSO options, contact support@techeval.ai.