K-OTP

Console guide

Managing apps, keys, usage, and credits in the console

The console (app.k-otp.dev) is where you manage K-OTP apps, keys, usage, and credits.

The console UI is still being built, so menu names and layout may change. This page focuses on concepts.

Apps

An app is the basic unit of K-OTP. Create one app per service (or environment). For example, separate production and staging apps keep keys, credits, and issue history apart.

An app owns:

  • API keys (pk_, sk_)
  • a credit wallet (shared by all of its keys)
  • issue history and the credit ledger

Keys

Issue keys per purpose inside an app.

  • Server sk_ keys — pick only the scopes you need: otp:issue and otp:verify for a server that issues and verifies; add otp:dashboard:read, otp:ledger:read, otp:balance, etc. for admin screens or billing jobs.
  • Browser pk_ keys — can only hold otp:issue and otp:verify, and you must register the exact origins allowed to call with them (for example https://www.example.com). Wildcards are not supported.

Treat key values like passwords. For rotation, revocation, and propagation time (up to about 60 seconds), see Authentication › Rotating and revoking keys.

Usage

The console shows issue history and delivery/verification status. The same data is available through the API:

History never includes phone numbers, codes, idempotency keys, or metadata.

Credits

Top up credits and review the balance and ledger in the console. Issues are rejected with 402 PAYMENT_REQUIRED when credit runs out, so keep enough headroom for your traffic. See Credits & billing.

On this page