API authentication
Which Streakfox credentials are public, which stay on your server, and where to find them.
Project key (public)
Your project key identifies your project. It's safe in a web page, so the widget uses it as data-project. The webhook URL and the state endpoint carry it too, as /v1/webhook/YOUR_PROJECT_KEY/e and ?siteKey=YOUR_PROJECT_KEY.
A project key alone can't count actions. Browser requests that read state must also come from your website address saved in Streakfox.
Webhook secret (server only)
The webhook secret lets your server or automation count actions. Send it in the X-Streak-Webhook-Secret header on POST /v1/webhook/YOUR_PROJECT_KEY/e.
POST /v1/webhook/YOUR_PROJECT_KEY/e HTTP/1.1
Host: api.streakfox.com
X-Streak-Webhook-Secret: YOUR_WEBHOOK_SECRET
Content-Type: application/jsonFind it in onboarding on the Connect the action step, or under Programs → Connections. Keep it in server environment variables or your automation tool's secret store. Never put it in a page, a browser script or a public repository.
If it leaks, rotate it with the create_or_rotate_webhook_secret MCP tool or email support@streakfox.com. Then update every sender with the new secret.
Identity tokens (protected rewards)
Coupon and link rewards are revealed only to a member with a short-lived, server-signed identity token. The widget sends it as data-identity-token. The WordPress plugin signs and refreshes these tokens for you. Connecting users describes the token format.
MCP bearer token
The MCP endpoint requires Authorization: Bearer <token>. See MCP for setup.