Write keys
Understand the public browser key in your Website's snippet and when to rotate it.
Each Website has a browser write key in the snippet shown under Website → Settings → Tracking. The browser sends it with pageviews, custom events, and identity updates. Graytower checks the key and the request origin against the Website's registered domains.
Browser key versus server key
| Key | Where it belongs | What it does |
|---|---|---|
| Browser write key | Public tracking snippet | Sends browser events from registered roots. |
| Custom events server key | Backend secret store | Sends server custom events. |
| Stripe attribution server key | Backend secret store | Sends authenticated Stripe attribution context. |
This key is meant to appear in browser code. It is not a server secret and does not grant access to your analytics reports. Do not use it as a Bearer token for the server Events API. If you rotate the Website's write key in Settings, deploy the updated snippet to every tracked host so collection continues.
Rotate safely
After rotation, recopy the snippet and update every host that uses the old key. Confirm a new accepted pageview under Website → Settings → Tracking. Requests using the old browser key will no longer authenticate.
Use server authentication for backend events or Stripe attribution calls.