Ingest key
An ingest key is the key a tracking script or a server uses to send events into one analytics project, with no right to read data back.
Analytics tools separate two kinds of credential. An ingest key, also called a write key or project key, lets a client send events. An API key lets a program read reports. The split exists because the ingest key has to live where visitors can see it: in the page source of a website.
A key that can only add events to one project is safe to publish. Someone who copies it can send data to that project and read nothing from it. Keys used by servers are different: they stay on the server and are treated as secrets.
In MIRA FIVE
Each source has its own keys, on its Ingest keys tab, and they come in two kinds. The website key of a website source sits in the script tag as data-key, where anyone viewing the page can read it; only the source’s allowed origins may send with it. The secret key of a server source is shown once, lives in MIRAFIVE_SECRET_KEY on your backend and never reaches a browser. Server SDKs for Node.js, PHP, Laravel and others, or plain HTTP to https://events.mirafive.io/v1/batch, send events with it.
Reading data back takes a personal API key or OAuth. A key can be revoked, and its source then stops accepting it.