Server authentication
Create a Website-scoped server key and send it only from trusted backend code.
Create a server API key in Website settings and choose its purpose: Custom events for POST /api/collect/server, or Stripe attribution for the authenticated Stripe attribution endpoint. The purposes are separate; use the key intended for the endpoint.
Store and send the key
Authorization: Bearer YOUR_SERVER_KEY
Content-Type: application/jsonStore the secret in your server environment and send it as Authorization: Bearer YOUR_SERVER_KEY. Do not put it in a browser bundle, HTML, client-side environment variable, or public repository. Graytower displays the full generated secret when it is created; retain it securely. A revoked key stops working, so update the deployed server configuration when rotating one.
Rotate or revoke
Create a replacement key with the same purpose, update your backend secret, then revoke the old key. Test the relevant endpoint with the replacement key before relying on it in production.
Server keys are scoped to one Website. A browser write key in the tracking snippet has a different role and cannot authenticate a server request.